dnssec-signzone.docbook revision 61271cdee65f3313e98f382b07e6674861d9020a
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
edd6c1f4be1aa23fc99134802941397f7f31b3d5jerenkrantz "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
edd6c1f4be1aa23fc99134802941397f7f31b3d5jerenkrantz [<!ENTITY mdash "—">]>
edd6c1f4be1aa23fc99134802941397f7f31b3d5jerenkrantz - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
d7d551e53cdfb3288eb651447d7209599c40d17estoddard - Copyright (C) 2000-2003 Internet Software Consortium.
d7d551e53cdfb3288eb651447d7209599c40d17estoddard - Permission to use, copy, modify, and/or distribute this software for any
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz - purpose with or without fee is hereby granted, provided that the above
956a1511249b1fec73aaee0fb7d69c8492aa1368aaron - copyright notice and this permission notice appear in all copies.
956a1511249b1fec73aaee0fb7d69c8492aa1368aaron - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
956a1511249b1fec73aaee0fb7d69c8492aa1368aaron - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron - PERFORMANCE OF THIS SOFTWARE.
d0e4ca9bfd8bf44bea574733965851bfee939d95aaron<!-- $Id: dnssec-signzone.docbook,v 1.45 2011/03/04 22:20:20 each Exp $ -->
a4b3fb28f3d2e0983b15b4c6828c6980f2fc9b15jerenkrantz <refentryinfo>
548b2980e83f609186a76e98fb245d02e8547bc3jerenkrantz </refentryinfo>
e54b09d79ca9bc18ea5ae33367fd907473621dcejerenkrantz <refentrytitle><application>dnssec-signzone</application></refentrytitle>
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz <refnamediv>
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz <refname><application>dnssec-signzone</application></refname>
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz <refpurpose>DNSSEC zone signing tool</refpurpose>
edcd9e6d9d29f60b25f7b9779dbd33e9dc1cc79ejerenkrantz </refnamediv>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe </copyright>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <copyright>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe </copyright>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <refsynopsisdiv>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <cmdsynopsis>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
1582553026e5e3a1921a34222eaee923fddee9b9wrowe <arg><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
bd214bbc8d9db9d6d1dcb6b24462e6d1da8e8bbbstoddard <arg><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
bd214bbc8d9db9d6d1dcb6b24462e6d1da8e8bbbstoddard <arg><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
bd214bbc8d9db9d6d1dcb6b24462e6d1da8e8bbbstoddard <arg><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
1078b2c97bb39352bae929d2ed3f290a420470a7ianh <arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
762c82a23cc3ddaac92f941b2f871e94efdf4e6bgregames <arg><option>-k <replaceable class="parameter">key</replaceable></option></arg>
762c82a23cc3ddaac92f941b2f871e94efdf4e6bgregames <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
762c82a23cc3ddaac92f941b2f871e94efdf4e6bgregames <arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
fb50cf6056a42f94cc9e8eeabea1eb8d05e0aefcaaron <arg><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
fb50cf6056a42f94cc9e8eeabea1eb8d05e0aefcaaron <arg><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
fb50cf6056a42f94cc9e8eeabea1eb8d05e0aefcaaron <arg><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
fb50cf6056a42f94cc9e8eeabea1eb8d05e0aefcaaron <arg><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
fb50cf6056a42f94cc9e8eeabea1eb8d05e0aefcaaron <arg><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
d56c38bfb6293bfff7c980858b19e32039106618jerenkrantz <arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
7c301a1818939f85da8f3629cc3e9b5588610ef0jerenkrantz <arg><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
7c301a1818939f85da8f3629cc3e9b5588610ef0jerenkrantz <arg><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
a7fb6d64e059872d5410e873b7f492d62a5cf916rbb <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
a7fb6d64e059872d5410e873b7f492d62a5cf916rbb <arg><option>-X <replaceable class="parameter">extended end-time</replaceable></option></arg>
a985ccb3ebd4be0fda23a0ce9ad95fd233089463trawick <arg><option>-3 <replaceable class="parameter">salt</replaceable></option></arg>
a985ccb3ebd4be0fda23a0ce9ad95fd233089463trawick <arg><option>-H <replaceable class="parameter">iterations</replaceable></option></arg>
af262486b3d1c33299307195a715bd1e373f99afrbb </cmdsynopsis>
af262486b3d1c33299307195a715bd1e373f99afrbb </refsynopsisdiv>
af262486b3d1c33299307195a715bd1e373f99afrbb <refsect1>
628ce9384209a460022be952ccdcc8538ad3ca84slive signs a zone. It generates
628ce9384209a460022be952ccdcc8538ad3ca84slive NSEC and RRSIG records and produces a signed version of the
628ce9384209a460022be952ccdcc8538ad3ca84slive zone. The security status of delegations from the signed zone
628ce9384209a460022be952ccdcc8538ad3ca84slive (that is, whether the child zones are secure or not) is
2b9a9a94658c0febcad2f76621b2d5ab856edc6atrawick determined by the presence or absence of a
2b9a9a94658c0febcad2f76621b2d5ab856edc6atrawick <filename>keyset</filename> file for each child zone.
2b9a9a94658c0febcad2f76621b2d5ab856edc6atrawick </refsect1>
f6f453bf03007f391d347dc821e507cdd924d1bftrawick <variablelist>
205f4595abf32ae208958d7f8abea68b335c9f39trawick <varlistentry>
1078b2c97bb39352bae929d2ed3f290a420470a7ianh Verify all generated signatures.
1078b2c97bb39352bae929d2ed3f290a420470a7ianh </listitem>
1078b2c97bb39352bae929d2ed3f290a420470a7ianh </varlistentry>
1078b2c97bb39352bae929d2ed3f290a420470a7ianh <varlistentry>
1078b2c97bb39352bae929d2ed3f290a420470a7ianh <term>-c <replaceable class="parameter">class</replaceable></term>
b6135e7458bf348c694157b042786562d2b86e18ianh <listitem>
611e46c801a6bd62e58a7f68abe1d2bbba473a92aaron Specifies the DNS class of the zone.
611e46c801a6bd62e58a7f68abe1d2bbba473a92aaron </listitem>
611e46c801a6bd62e58a7f68abe1d2bbba473a92aaron </varlistentry>
4224d5789080ea5586d49420da1e1996f5653bb5ianh <varlistentry>
2d2e3667d789f527a04ce6a0089621470c8143ccmartin Compatibility mode: Generate a
2d2e3667d789f527a04ce6a0089621470c8143ccmartin <filename>keyset-<replaceable>zonename</replaceable></filename>
2d2e3667d789f527a04ce6a0089621470c8143ccmartin file in addition to
2d2e3667d789f527a04ce6a0089621470c8143ccmartin <filename>dsset-<replaceable>zonename</replaceable></filename>
2d2e3667d789f527a04ce6a0089621470c8143ccmartin when signing a zone, for use by older versions of
2d2e3667d789f527a04ce6a0089621470c8143ccmartin </listitem>
9b0141308bc27f61d82742c198356975aa6b488abrianp </varlistentry>
9b0141308bc27f61d82742c198356975aa6b488abrianp <varlistentry>
fd3fa792f04fc9c4e8f5f83dceb0fc34e71f8570ianh <term>-d <replaceable class="parameter">directory</replaceable></term>
fd3fa792f04fc9c4e8f5f83dceb0fc34e71f8570ianh <listitem>
22d348febc3c258df246ac93e37945398dbf0348ianh <filename>keyset-</filename> files in <option>directory</option>.
7a95e47ff0d0e4306df0901d56131b49dca5691etrawick </listitem>
62af8654f682ca4913636bae099bec0befab985ctrawick </varlistentry>
62af8654f682ca4913636bae099bec0befab985ctrawick <varlistentry>
62af8654f682ca4913636bae099bec0befab985ctrawick <term>-E <replaceable class="parameter">engine</replaceable></term>
1e557a77c091a1d2f2872872a7c20e9f2ffccbc1aaron Uses a crypto hardware (OpenSSL engine) for the crypto operations
1e557a77c091a1d2f2872872a7c20e9f2ffccbc1aaron it supports, for instance signing with private keys from
5e98e52df07f59be456af01ebf46d81defef2385trawick a secure key store. When compiled with PKCS#11 support
5e98e52df07f59be456af01ebf46d81defef2385trawick it defaults to pkcs11; the empty name resets it to no engine.
5e98e52df07f59be456af01ebf46d81defef2385trawick </listitem>
7a95e47ff0d0e4306df0901d56131b49dca5691etrawick </varlistentry>
1e557a77c091a1d2f2872872a7c20e9f2ffccbc1aaron <varlistentry>
b393bdb2e1eabbe4b9b37c5eaeeeca799b2eb324stoddard Generate DS records for child zones from
6f912b4ad14f622aa8d57f887c8c745e13ff6dbfjerenkrantz <filename>dsset-</filename> or <filename>keyset-</filename>
3cd826b00280881e5a2f03d8ec1f8d55802b93dewrowe file. Existing DS records will be removed.
3cd826b00280881e5a2f03d8ec1f8d55802b93dewrowe </listitem>
3cd826b00280881e5a2f03d8ec1f8d55802b93dewrowe </varlistentry>
435c423bdcfa61ff871a9e289d1140f2bac839b8brianp <varlistentry>
435c423bdcfa61ff871a9e289d1140f2bac839b8brianp <term>-K <replaceable class="parameter">directory</replaceable></term>
e93cea6246ce30bf9791530a15c56f9e2eecf9cbianh Key repository: Specify a directory to search for DNSSEC keys.
e93cea6246ce30bf9791530a15c56f9e2eecf9cbianh If not specified, defaults to the current directory.
f65342c1467751310036d4f9d75f554eaaf01cc6wrowe </listitem>
960eba6c6d512880c3ed0516f5d15c6e7bc7581ajerenkrantz </varlistentry>
960eba6c6d512880c3ed0516f5d15c6e7bc7581ajerenkrantz <varlistentry>
45613d36b9466a48def0498cffa07f48980720f8jerenkrantz <term>-k <replaceable class="parameter">key</replaceable></term>
6f912b4ad14f622aa8d57f887c8c745e13ff6dbfjerenkrantz Treat specified key as a key signing key ignoring any
6f912b4ad14f622aa8d57f887c8c745e13ff6dbfjerenkrantz key flags. This option may be specified multiple times.
1abe6003aeb198cc97263503bceed457a6c2cb4aaaron </listitem>
1abe6003aeb198cc97263503bceed457a6c2cb4aaaron </varlistentry>
cbd8d35ca8d9780f1081f30ebfe4abda44cab7ebianh <varlistentry>
cbd8d35ca8d9780f1081f30ebfe4abda44cab7ebianh <term>-l <replaceable class="parameter">domain</replaceable></term>
cbd8d35ca8d9780f1081f30ebfe4abda44cab7ebianh <listitem>
cbd8d35ca8d9780f1081f30ebfe4abda44cab7ebianh Generate a DLV set in addition to the key (DNSKEY) and DS sets.
0dc14774d2c21baf6123fcafdb853af5be1d97edwrowe The domain is appended to the name of the records.
3ad5a1fa75e728431fa7b8e3d8a74bcadcd79d4dlars </listitem>
3ad5a1fa75e728431fa7b8e3d8a74bcadcd79d4dlars </varlistentry>
3fde4c273ea649d1320ec9c51e7d096cd9340a94jerenkrantz <varlistentry>
3fde4c273ea649d1320ec9c51e7d096cd9340a94jerenkrantz <term>-s <replaceable class="parameter">start-time</replaceable></term>
0dc14774d2c21baf6123fcafdb853af5be1d97edwrowe Specify the date and time when the generated RRSIG records
0dc14774d2c21baf6123fcafdb853af5be1d97edwrowe become valid. This can be either an absolute or relative
741a54303329728b27fe347447a362e1c576135etrawick time. An absolute start time is indicated by a number
0dc14774d2c21baf6123fcafdb853af5be1d97edwrowe in YYYYMMDDHHMMSS notation; 20000530144500 denotes
9f62694a8b4e2b88994a14555d144b3836b311cfstoddard 14:45:00 UTC on May 30th, 2000. A relative start time is
9f62694a8b4e2b88994a14555d144b3836b311cfstoddard indicated by +N, which is N seconds from the current time.
9f62694a8b4e2b88994a14555d144b3836b311cfstoddard If no <option>start-time</option> is specified, the current
9f62694a8b4e2b88994a14555d144b3836b311cfstoddard time minus 1 hour (to allow for clock skew) is used.
52489511342e4ff3fe399e57f29d38e5c4227bc8trawick </listitem>
52489511342e4ff3fe399e57f29d38e5c4227bc8trawick </varlistentry>
8864d6f5f4744b5d2b638e2a53e2660bcf8b5ab5dougm <varlistentry>
8864d6f5f4744b5d2b638e2a53e2660bcf8b5ab5dougm <term>-e <replaceable class="parameter">end-time</replaceable></term>
1e83c8de3aa48b316b28057d53995272baf1260cwrowe Specify the date and time when the generated RRSIG records
1dfb5e008f35ed13c343b7f6306675e33c399792gstein expire. As with <option>start-time</option>, an absolute
1dfb5e008f35ed13c343b7f6306675e33c399792gstein time is indicated in YYYYMMDDHHMMSS notation. A time relative
1dfb5e008f35ed13c343b7f6306675e33c399792gstein to the start time is indicated with +N, which is N seconds from
1dfb5e008f35ed13c343b7f6306675e33c399792gstein the start time. A time relative to the current time is
eadb64379834961679105b7fd4178253fbb9f95dtrawick indicated with now+N. If no <option>end-time</option> is
eadb64379834961679105b7fd4178253fbb9f95dtrawick specified, 30 days from the start time is used as a default.
c7e917aa56886c47bfe061c5e9f603a5aaef0d87trawick </listitem>
c7e917aa56886c47bfe061c5e9f603a5aaef0d87trawick </varlistentry>
b8daf4c5ea3d5bb2111b1b021de6d3cd891e403bcoar <varlistentry>
b8daf4c5ea3d5bb2111b1b021de6d3cd891e403bcoar <term>-X <replaceable class="parameter">extended end-time</replaceable></term>
b8daf4c5ea3d5bb2111b1b021de6d3cd891e403bcoar <listitem>
b8daf4c5ea3d5bb2111b1b021de6d3cd891e403bcoar Specify the date and time when the generated RRSIG records
6b6083e6518007139257ee449c2af3032d2437d0trawick for the DNSKEY RRset will expire. This is to be used in cases
6b6083e6518007139257ee449c2af3032d2437d0trawick when the DNSKEY signatures need to persist longer than
6b6083e6518007139257ee449c2af3032d2437d0trawick signatures on other records; e.g., when the private component
88dd056b9863502bba82c2889a0c4cde9fc0ba93trawick of the KSK is kept offline and the KSK signature is to be
88dd056b9863502bba82c2889a0c4cde9fc0ba93trawick refreshed manually.
7ef3a1797818c6d25efe8c5fadb5eec3b965a6fabrianp time is indicated in YYYYMMDDHHMMSS notation. A time relative
7ef3a1797818c6d25efe8c5fadb5eec3b965a6fabrianp to the start time is indicated with +N, which is N seconds from
1e83c8de3aa48b316b28057d53995272baf1260cwrowe the start time. A time relative to the current time is
1e83c8de3aa48b316b28057d53995272baf1260cwrowe indicated with now+N. If no <option>extended end-time</option> is
1e83c8de3aa48b316b28057d53995272baf1260cwrowe specified, the value of <option>end-time</option> is used as
1e83c8de3aa48b316b28057d53995272baf1260cwrowe the default. (<option>end-time</option>, in turn, defaults to
1e83c8de3aa48b316b28057d53995272baf1260cwrowe 30 days from the start time.) <option>extended end-time</option>
1e83c8de3aa48b316b28057d53995272baf1260cwrowe </listitem>
1e83c8de3aa48b316b28057d53995272baf1260cwrowe </varlistentry>
7f683bb300df767164724ebc664f339ac396b434dougm <varlistentry>
7f683bb300df767164724ebc664f339ac396b434dougm <term>-f <replaceable class="parameter">output-file</replaceable></term>
7f683bb300df767164724ebc664f339ac396b434dougm The name of the output file containing the signed zone. The
26dfa083a1662d57ba7cc410eec4e0696b9be469wrowe input filename.
26dfa083a1662d57ba7cc410eec4e0696b9be469wrowe </listitem>
26dfa083a1662d57ba7cc410eec4e0696b9be469wrowe </varlistentry>
4760aa1f19600972cf531ad7da73c1ee5a0225cedougm <varlistentry>
e93d563852e1fa7a8c73af3b807916b41942d2f6dreid Prints a short summary of the options and arguments to
e93d563852e1fa7a8c73af3b807916b41942d2f6dreid </listitem>
e93d563852e1fa7a8c73af3b807916b41942d2f6dreid </varlistentry>
525508562a53864b78cf8da91ac13be9c072bba7jerenkrantz <varlistentry>
525508562a53864b78cf8da91ac13be9c072bba7jerenkrantz <term>-i <replaceable class="parameter">interval</replaceable></term>
f1fe10268cdadb775eef841aa4fa7305291d35fdtrawick When a previously-signed zone is passed as input, records
f1fe10268cdadb775eef841aa4fa7305291d35fdtrawick may be resigned. The <option>interval</option> option
f04ad0ba7fe0eea5ea7a92f852cef75747ab2090trawick specifies the cycle interval as an offset from the current
f04ad0ba7fe0eea5ea7a92f852cef75747ab2090trawick time (in seconds). If a RRSIG record expires after the
f04ad0ba7fe0eea5ea7a92f852cef75747ab2090trawick cycle interval, it is retained. Otherwise, it is considered
65a1588701f9e5d0f62261d0da85733a23edc92ftrawick to be expiring soon, and it will be replaced.
65a1588701f9e5d0f62261d0da85733a23edc92ftrawick The default cycle interval is one quarter of the difference
65a1588701f9e5d0f62261d0da85733a23edc92ftrawick between the signature end and start times. So if neither
d5d164b22a2004abed640cb52fc275f00ed92f69jerenkrantz <option>end-time</option> or <option>start-time</option>
d5d164b22a2004abed640cb52fc275f00ed92f69jerenkrantz are specified, <command>dnssec-signzone</command>
360a9d933a8c25f5975e0ddc883607a5d37e408estoddard signatures that are valid for 30 days, with a cycle
360a9d933a8c25f5975e0ddc883607a5d37e408estoddard interval of 7.5 days. Therefore, if any existing RRSIG records
360a9d933a8c25f5975e0ddc883607a5d37e408estoddard are due to expire in less than 7.5 days, they would be
9b8afc47122e9b0eabb860b6ba2cf9c061c6060fstoddard </listitem>
9b8afc47122e9b0eabb860b6ba2cf9c061c6060fstoddard </varlistentry>
a21148678a1459064627d917a66669e7e8d140e6stoddard <varlistentry>
a21148678a1459064627d917a66669e7e8d140e6stoddard <term>-I <replaceable class="parameter">input-format</replaceable></term>
c6a9d49433c9ba5b18b26c3d764f1bbcb9746090wrowe The format of the input zone file.
c6a9d49433c9ba5b18b26c3d764f1bbcb9746090wrowe Possible formats are <command>"text"</command> (default)
51be7fc538641ed7cb22e959eb31629f7183f70fianh This option is primarily intended to be used for dynamic
bb6a7fc0427d0d197c50de34b94a0d23e5732696wrowe signed zones so that the dumped zone file in a non-text
bb6a7fc0427d0d197c50de34b94a0d23e5732696wrowe format containing updates can be signed directly.
bb6a7fc0427d0d197c50de34b94a0d23e5732696wrowe The use of this option does not make much sense for
bb6a7fc0427d0d197c50de34b94a0d23e5732696wrowe non-dynamic zones.
decd0c23bb26f6662f4b963cf86ee569613bffeagregames </listitem>
decd0c23bb26f6662f4b963cf86ee569613bffeagregames </varlistentry>
e1753aabf5df187b5b04e72a958af4b65b1a125daaron <varlistentry>
e1753aabf5df187b5b04e72a958af4b65b1a125daaron <term>-j <replaceable class="parameter">jitter</replaceable></term>
e1753aabf5df187b5b04e72a958af4b65b1a125daaron When signing a zone with a fixed signature lifetime, all
e1753aabf5df187b5b04e72a958af4b65b1a125daaron RRSIG records issued at the time of signing expires
e57f991fe2b9a4c080cd50ca913a2a5693b096b5aaron simultaneously. If the zone is incrementally signed, i.e.
e57f991fe2b9a4c080cd50ca913a2a5693b096b5aaron a previously-signed zone is passed as input to the signer,
e57f991fe2b9a4c080cd50ca913a2a5693b096b5aaron all expired signatures have to be regenerated at about the
924c8dd40352ca7775704a31a7a77ab86dc951b4ianh same time. The <option>jitter</option> option specifies a
924c8dd40352ca7775704a31a7a77ab86dc951b4ianh jitter window that will be used to randomize the signature
910df8b3f50a0515b430b999d4750de94c509f2atrawick expire time, thus spreading incremental signature
910df8b3f50a0515b430b999d4750de94c509f2atrawick regeneration over time.
0d628dd174dd6de13463b10d2599f6cac24e9fe8brianp Signature lifetime jitter also to some extent benefits
0d628dd174dd6de13463b10d2599f6cac24e9fe8brianp validators and servers by spreading out cache expiration,
0d628dd174dd6de13463b10d2599f6cac24e9fe8brianp i.e. if large numbers of RRSIGs don't expire at the same time
2fee4fe267fa3577fd71d8c314fe9b527e2b90c0brianp from all caches there will be less congestion than if all
2fee4fe267fa3577fd71d8c314fe9b527e2b90c0brianp validators need to refetch at mostly the same time.
2fee4fe267fa3577fd71d8c314fe9b527e2b90c0brianp </listitem>
7bf77d70b6830636bc36e6b76a228c301be23ff7brianp </varlistentry>
7bf77d70b6830636bc36e6b76a228c301be23ff7brianp <varlistentry>
185b73b1f914e5d8f99f31225cc656b882dcbf73ianh <term>-n <replaceable class="parameter">ncpus</replaceable></term>
cef5cb47e2ea4c174c01762d4430613db0f41e5cstoddard Specifies the number of threads to use. By default, one
cef5cb47e2ea4c174c01762d4430613db0f41e5cstoddard thread is started for each detected CPU.
8abd60101b9794e224795ccf68b8ba984efbc94astoddard </listitem>
8abd60101b9794e224795ccf68b8ba984efbc94astoddard </varlistentry>
ca47a2b6bcea23e8af185c68f256dcbbfd2a0f9dtrawick <varlistentry>
6ef713e25735887d4a59a879b97a68bd575ecb92trawick <term>-N <replaceable class="parameter">soa-serial-format</replaceable></term>
26d590c0e5338f66ca1aad6f925374843fac5121stoddard The SOA serial number format of the signed zone.
26d590c0e5338f66ca1aad6f925374843fac5121stoddard Possible formats are <command>"keep"</command> (default),
d472f67198d6b15dd1270136f180cca9c9263243trawick <variablelist>
d472f67198d6b15dd1270136f180cca9c9263243trawick <varlistentry>
d472f67198d6b15dd1270136f180cca9c9263243trawick </listitem>
d472f67198d6b15dd1270136f180cca9c9263243trawick </varlistentry>
a3bb95a3600153c7f09f62749e32093658943c32brianp <varlistentry>
b760518cc17e7124ba546ed63063603f1ab82a40aaron <para>Increment the SOA serial number using RFC 1982
b760518cc17e7124ba546ed63063603f1ab82a40aaron arithmetics.</para>
b760518cc17e7124ba546ed63063603f1ab82a40aaron </listitem>
b760518cc17e7124ba546ed63063603f1ab82a40aaron </varlistentry>
b760518cc17e7124ba546ed63063603f1ab82a40aaron <varlistentry>
23d8f62856c1531526042e1c5edf44557cadd2e5trawick <para>Set the SOA serial number to the number of seconds
23d8f62856c1531526042e1c5edf44557cadd2e5trawick since epoch.</para>
705c8ed3ef608706c91ca12483d7b54ff9007cc9jerenkrantz </varlistentry>
705c8ed3ef608706c91ca12483d7b54ff9007cc9jerenkrantz </variablelist>
ef154948c97c53cdc1ad5329cb83c32ad26cf416aaron </listitem>
ef154948c97c53cdc1ad5329cb83c32ad26cf416aaron </varlistentry>
c6741d11357aace4c9ba39535d3cb2d751f46114trawick <varlistentry>
c6741d11357aace4c9ba39535d3cb2d751f46114trawick <term>-o <replaceable class="parameter">origin</replaceable></term>
7230f1eb017a35b7d20e0e9ec0d234766f2a732dtrawick The zone origin. If not specified, the name of the zone file
86a5d34400b7f586ad2cca97c8b33b2f55bac61btrawick is assumed to be the origin.
86a5d34400b7f586ad2cca97c8b33b2f55bac61btrawick </listitem>
86a5d34400b7f586ad2cca97c8b33b2f55bac61btrawick </varlistentry>
86a5d34400b7f586ad2cca97c8b33b2f55bac61btrawick <varlistentry>
86a5d34400b7f586ad2cca97c8b33b2f55bac61btrawick <term>-O <replaceable class="parameter">output-format</replaceable></term>
6b477c0a238733ca8fd156629310513d29dc7e02trawick The format of the output file containing the signed zone.
6b477c0a238733ca8fd156629310513d29dc7e02trawick Possible formats are <command>"text"</command> (default)
557eb8d48357657fa898250560f089c65539c634gregames </listitem>
557eb8d48357657fa898250560f089c65539c634gregames </varlistentry>
adb8c5e5291be5943122bbff404bc1018c79d555ianh <varlistentry>
25b715e9687f82ea055fdea2a9761c7e5f1ac6eetrawick Use pseudo-random data when signing the zone. This is faster,
51ced3b28ef430a96586284d4320f7dbdaf7225ebrianp but less secure, than using real random data. This option
51ced3b28ef430a96586284d4320f7dbdaf7225ebrianp may be useful when signing large zones or when the entropy
51ced3b28ef430a96586284d4320f7dbdaf7225ebrianp source is limited.
a222035458f89e2db231450ba6d5fae8052da5f5aaron </listitem>
a222035458f89e2db231450ba6d5fae8052da5f5aaron </varlistentry>
4a872628ca5bf20847f442a625c255b643120db0wrowe <varlistentry>
74528257888620220641cd28366731539a37e1f3ianh Disable post sign verification tests.
0632de713e41fa3aa928a1777677b0d79843ae2bdougm The post sign verification test ensures that for each algorithm
0cc82c261350ab8dc8a9992cad7197c4d22d597eianh in use there is at least one non revoked self signed KSK key,
f2afeedf074acc1a698a9527154eacd138e6c5a1trawick that all revoked KSK keys are self signed, and that all records
855e263a93fde2e30d10a48a9ffc047039bfc9d9brianp in the zone are signed by the algorithm.
855e263a93fde2e30d10a48a9ffc047039bfc9d9brianp This option skips these tests.
855e263a93fde2e30d10a48a9ffc047039bfc9d9brianp </listitem>
54b3b7946d22324cea615d7c8a4ff0c9eadd1f8crbb </varlistentry>
54b3b7946d22324cea615d7c8a4ff0c9eadd1f8crbb <varlistentry>
54b3b7946d22324cea615d7c8a4ff0c9eadd1f8crbb <term>-r <replaceable class="parameter">randomdev</replaceable></term>
54b3b7946d22324cea615d7c8a4ff0c9eadd1f8crbb <listitem>
e28c02dc08247d3fcb71e81791cac2311a248dfdrbb Specifies the source of randomness. If the operating
e28c02dc08247d3fcb71e81791cac2311a248dfdrbb system does not provide a <filename>/dev/random</filename>
e28c02dc08247d3fcb71e81791cac2311a248dfdrbb or equivalent device, the default source of randomness
e28c02dc08247d3fcb71e81791cac2311a248dfdrbb the name of a character device or file containing random
f9f506f0686ad065b4c6fe14dd962cdd478350dbianh data to be used instead of the default. The special value
f9f506f0686ad065b4c6fe14dd962cdd478350dbianh input should be used.
9d0665da83d1e22c0ea0e5f6f940f70f75bf5237ianh </listitem>
9d0665da83d1e22c0ea0e5f6f940f70f75bf5237ianh </varlistentry>
9d0665da83d1e22c0ea0e5f6f940f70f75bf5237ianh <varlistentry>
47c2fb4c1f155ddb6954e46e7f6d125eef78b3bbaaron Smart signing: Instructs <command>dnssec-signzone</command> to
9ca934cec0a1cc3c425fde5dc51956bce6cd3183brianp search the key repository for keys that match the zone being
9ca934cec0a1cc3c425fde5dc51956bce6cd3183brianp signed, and to include them in the zone if appropriate.
0cdca1e056a05a09fe16fe736abcf79969c9767ejerenkrantz When a key is found, its timing metadata is examined to
0cdca1e056a05a09fe16fe736abcf79969c9767ejerenkrantz determine how it should be used, according to the following
f2afeedf074acc1a698a9527154eacd138e6c5a1trawick rules. Each successive rule takes priority over the prior
0a2d57d962bef3a8898723925b3fb02d2e836994dougm <variablelist>
0a2d57d962bef3a8898723925b3fb02d2e836994dougm <varlistentry>
06461d67f387ea068187e6dfa036875a8205c04cjerenkrantz If no timing metadata has been set for the key, the key is
900127764fb985c340ee4979cac97146a330c694trawick published in the zone and used to sign the zone.
1a6a0072a95887164091e366ba0e89c2b39a954abrianp </listitem>
1a6a0072a95887164091e366ba0e89c2b39a954abrianp </varlistentry>
6f4c27ba6e152792f3729069e8d8313ebc87cc60jwoolley <varlistentry>
23ce412bd50a47accab4dd26019b78810bbf46ebtrawick If the key's publication date is set and is in the past, the
23ce412bd50a47accab4dd26019b78810bbf46ebtrawick key is published in the zone.
6865813dee5d3c1ebf12dd810368171792a0190atrawick </listitem>
6865813dee5d3c1ebf12dd810368171792a0190atrawick </varlistentry>
97719ad970d779ac48af9364ab0ea9fdcc27470ajwoolley <varlistentry>
5ad238c42b1e159ee8f164515e0c4ee6c727c2fdtrawick If the key's activation date is set and in the past, the
5ad238c42b1e159ee8f164515e0c4ee6c727c2fdtrawick key is published (regardless of publication date) and
5ad238c42b1e159ee8f164515e0c4ee6c727c2fdtrawick used to sign the zone.
ba00c3b7c20f00ce631b89ae3b1cd3bae8d1b165rbb </listitem>
ba00c3b7c20f00ce631b89ae3b1cd3bae8d1b165rbb </varlistentry>
ba00c3b7c20f00ce631b89ae3b1cd3bae8d1b165rbb <varlistentry>
ba00c3b7c20f00ce631b89ae3b1cd3bae8d1b165rbb <listitem>
6e954603b02f2b7d4ad80af17d9b3cc6f0bacf69rbb If the key's revocation date is set and in the past, and the
6e954603b02f2b7d4ad80af17d9b3cc6f0bacf69rbb key is published, then the key is revoked, and the revoked key
6e954603b02f2b7d4ad80af17d9b3cc6f0bacf69rbb is used to sign the zone.
6e954603b02f2b7d4ad80af17d9b3cc6f0bacf69rbb </listitem>
6e954603b02f2b7d4ad80af17d9b3cc6f0bacf69rbb </varlistentry>
fa449f5bc87c5d87c4c60e778c9c882e7254de7ejwoolley <varlistentry>
fa449f5bc87c5d87c4c60e778c9c882e7254de7ejwoolley If either of the key's unpublication or deletion dates are set
fa449f5bc87c5d87c4c60e778c9c882e7254de7ejwoolley and in the past, the key is NOT published or used to sign the
1c0b7c3bdace07946457fa7ba04b7f97b6599792rbb zone, regardless of any other metadata.
227d23a7db41dd89f52391c9356dbb1adcd675e0jwoolley </listitem>
227d23a7db41dd89f52391c9356dbb1adcd675e0jwoolley </varlistentry>
227d23a7db41dd89f52391c9356dbb1adcd675e0jwoolley </variablelist>
227d23a7db41dd89f52391c9356dbb1adcd675e0jwoolley </listitem>
227d23a7db41dd89f52391c9356dbb1adcd675e0jwoolley </varlistentry>
17bc0e8f2e3816e25bc8fd3fadf39357340aebd0jerenkrantz <varlistentry>
17bc0e8f2e3816e25bc8fd3fadf39357340aebd0jerenkrantz <term>-T <replaceable class="parameter">ttl</replaceable></term>
17bc0e8f2e3816e25bc8fd3fadf39357340aebd0jerenkrantz Specifies the TTL to be used for new DNSKEY records imported
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb into the zone from the key repository. If not specified,
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb the default is the minimum TTL value from the zone's SOA
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb record. This option is ignored when signing without
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb <option>-S</option>, since DNSKEY records are not imported
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb from the key repository in that case. It is also ignored if
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb there are any pre-existing DNSKEY records at the zone apex,
e6cc28a5eb3371ba0c38e941855e71ff0054f50erbb in which case new records' TTL values will be set to match
cf233fb4b439415a2bf7bab7e622afd994e0bebftrawick </listitem>
cf233fb4b439415a2bf7bab7e622afd994e0bebftrawick </varlistentry>
ae64f3e7385f21ca9d4f30cc7f8702a9ac1034b6trawick <varlistentry>
2a20a2f8432a15b530e0a6b0998c32f40aef82a8gregames Print statistics at completion.
2a20a2f8432a15b530e0a6b0998c32f40aef82a8gregames </listitem>
2a20a2f8432a15b530e0a6b0998c32f40aef82a8gregames </varlistentry>
2a20a2f8432a15b530e0a6b0998c32f40aef82a8gregames <varlistentry>
f99bffd6087564cf9c05cc29d1c6b38d94e0ed30gregames Update NSEC/NSEC3 chain when re-signing a previously signed
270609308f247c5e934b400b5f1691c2cca16c61jerenkrantz zone. With this option, a zone signed with NSEC can be
270609308f247c5e934b400b5f1691c2cca16c61jerenkrantz switched to NSEC3, or a zone signed with NSEC3 can
270609308f247c5e934b400b5f1691c2cca16c61jerenkrantz be switch to NSEC or to NSEC3 with different parameters.
8458877c9ba0af86acd590eea531476adde3d02dmartin Without this option, <command>dnssec-signzone</command> will
8458877c9ba0af86acd590eea531476adde3d02dmartin retain the existing chain when re-signing.
8458877c9ba0af86acd590eea531476adde3d02dmartin </listitem>
8458877c9ba0af86acd590eea531476adde3d02dmartin </varlistentry>
644be6f54749d2d9950d2c4d2ac448f7af016d26martin <varlistentry>
644be6f54749d2d9950d2c4d2ac448f7af016d26martin <term>-v <replaceable class="parameter">level</replaceable></term>
b30b04f639d479b96cc08c43ffa34c92ba275676ianh Sets the debugging level.
b30b04f639d479b96cc08c43ffa34c92ba275676ianh </listitem>
c4fbc4018fd2b6716673a38ee27eeb36cba41c5djwoolley </varlistentry>
c4fbc4018fd2b6716673a38ee27eeb36cba41c5djwoolley <varlistentry>
f4e4643c309e5b5da60e13f9a25984d54b307caawrowe Only sign the DNSKEY RRset with key-signing keys, and omit
2548497d480c4f3e9b3fe14711bd510aa2157434gregames signatures from zone-signing keys. (This is similar to the
2548497d480c4f3e9b3fe14711bd510aa2157434gregames <command>dnssec-dnskey-kskonly yes;</command> zone option in
da6e93dca0222159650783802e23172e3160605egregames </varlistentry>
da6e93dca0222159650783802e23172e3160605egregames <varlistentry>
c927e13f298c42251296d33cc1fa3eb8232b843daaron Ignore KSK flag on key when determining what to sign. This
c927e13f298c42251296d33cc1fa3eb8232b843daaron causes KSK-flagged keys to sign all records, not just the
9126ed10455a2a98a3a51c68ed1b356e1873e8e6aaron DNSKEY RRset. (This is similar to the
9126ed10455a2a98a3a51c68ed1b356e1873e8e6aaron <command>update-check-ksk no;</command> zone option in
fa3ca21e09bac0dbc2045e9f53963ba46cfed5b1trawick </listitem>
fa3ca21e09bac0dbc2045e9f53963ba46cfed5b1trawick </varlistentry>
fa3ca21e09bac0dbc2045e9f53963ba46cfed5b1trawick <varlistentry>
18acb2c0df442ead1d075a1a2207cbb197725b14coar <term>-3 <replaceable class="parameter">salt</replaceable></term>
18acb2c0df442ead1d075a1a2207cbb197725b14coar <listitem>
18acb2c0df442ead1d075a1a2207cbb197725b14coar Generate an NSEC3 chain with the given hex encoded salt.
617f972690d850a52cd4e9ef2f32d356e0fae715aaron A dash (<replaceable class="parameter">salt</replaceable>) can
617f972690d850a52cd4e9ef2f32d356e0fae715aaron be used to indicate that no salt is to be used when generating the NSEC3 chain.
617f972690d850a52cd4e9ef2f32d356e0fae715aaron </listitem>
617f972690d850a52cd4e9ef2f32d356e0fae715aaron </varlistentry>
9278d5393ef084f4fc6d7ec8641af5959442c157jwoolley <varlistentry>
9278d5393ef084f4fc6d7ec8641af5959442c157jwoolley <term>-H <replaceable class="parameter">iterations</replaceable></term>
022cff78006f698453640e0a0e97cc5f8c9de59drbb <listitem>
022cff78006f698453640e0a0e97cc5f8c9de59drbb When generating an NSEC3 chain, use this many interations. The
022cff78006f698453640e0a0e97cc5f8c9de59drbb default is 10.
526a776292f420ffeea0d081c61971ed381fad20stoddard </listitem>
526a776292f420ffeea0d081c61971ed381fad20stoddard </varlistentry>
526a776292f420ffeea0d081c61971ed381fad20stoddard <varlistentry>
526a776292f420ffeea0d081c61971ed381fad20stoddard When generating an NSEC3 chain set the OPTOUT flag on all
526a776292f420ffeea0d081c61971ed381fad20stoddard NSEC3 records and do not generate NSEC3 records for insecure
526a776292f420ffeea0d081c61971ed381fad20stoddard delegations.
62ddc9851530478919d169ba9c34b80f60cf7718trawick Using this option twice (i.e., <option>-AA</option>)
62ddc9851530478919d169ba9c34b80f60cf7718trawick turns the OPTOUT flag off for all records. This is useful
62ddc9851530478919d169ba9c34b80f60cf7718trawick when using the <option>-u</option> option to modify an NSEC3
62ddc9851530478919d169ba9c34b80f60cf7718trawick chain which previously had OPTOUT set.
904d7bf799c6216beb34519463596b4fce630308wrowe </listitem>
904d7bf799c6216beb34519463596b4fce630308wrowe </varlistentry>
904d7bf799c6216beb34519463596b4fce630308wrowe <varlistentry>
904d7bf799c6216beb34519463596b4fce630308wrowe The file containing the zone to be signed.
17a4c6968b2fa692ff4dde12fe305230ee6b0421aaron </listitem>
17a4c6968b2fa692ff4dde12fe305230ee6b0421aaron </varlistentry>
83b031099aa3dc8a5fd2f708e397818cbd16c9aajerenkrantz <varlistentry>
01e77cadbd9ad4962993380245bcc033dde523e4rbb Specify which keys should be used to sign the zone. If
01e77cadbd9ad4962993380245bcc033dde523e4rbb no keys are specified, then the zone will be examined
8ea9794272347cfdd92861f46295406649f01afatrawick for DNSKEY records at the zone apex. If these are found and
8ea9794272347cfdd92861f46295406649f01afatrawick there are matching private keys, in the current directory,
8ea9794272347cfdd92861f46295406649f01afatrawick then these will be used for signing.
b900452c9c36031434d318880f023c0fb9143325rbb </listitem>
b900452c9c36031434d318880f023c0fb9143325rbb </varlistentry>
b900452c9c36031434d318880f023c0fb9143325rbb </variablelist>
b900452c9c36031434d318880f023c0fb9143325rbb </refsect1>
b900452c9c36031434d318880f023c0fb9143325rbb <refsect1>
43053faf24ffe7657bb32bc06d4058dedf3ef053rbb The following command signs the <userinput>example.com</userinput>
8b666e1fb772b6fe45de3604b224f3e1f2cfd620rbb zone with the DSA key generated by <command>dnssec-keygen</command>
c453a141db60a5b19649eac508f4851a8729c556rbb (Kexample.com.+003+17247). Because the <command>-S</command> option
c453a141db60a5b19649eac508f4851a8729c556rbb is not being used, the zone's keys must be in the master file
c453a141db60a5b19649eac508f4851a8729c556rbb (<filename>db.example.com</filename>). This invocation looks
8b91dcac0e1ef7796c72d16b0962267313cac486jerenkrantz for <filename>dsset</filename> files, in the current directory,
8b91dcac0e1ef7796c72d16b0962267313cac486jerenkrantz so that DS records can be imported from them (<command>-g</command>).
6ce942b017db75b559a42bdc2d7b8ea9e869a956wrowe<programlisting>% dnssec-signzone -g -o example.com db.example.com \
6ce942b017db75b559a42bdc2d7b8ea9e869a956wrowe%</programlisting>
6ce942b017db75b559a42bdc2d7b8ea9e869a956wrowe In the above example, <command>dnssec-signzone</command> creates
6ce942b017db75b559a42bdc2d7b8ea9e869a956wrowe the file <filename>db.example.com.signed</filename>. This
6ce942b017db75b559a42bdc2d7b8ea9e869a956wrowe file should be referenced in a zone statement in a
7dfed2b71c9c4223996cbd7c5c0c85c7c8fef2a4rbb This example re-signs a previously signed zone with default parameters.
574f6ff9ee80ef4f772649c5c8319b764a8abe42jerenkrantz The private keys are assumed to be in the current directory.
574f6ff9ee80ef4f772649c5c8319b764a8abe42jerenkrantz<programlisting>% cp db.example.com.signed db.example.com
6d7d70dbda8e461d87f2d41e323755496ae3ebc7trawick%</programlisting>
a310497ca9c5112d759871e1b7d9f6a40fb78bcfwrowe <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
a310497ca9c5112d759871e1b7d9f6a40fb78bcfwrowe </citerefentry>,
a310497ca9c5112d759871e1b7d9f6a40fb78bcfwrowe <citetitle>BIND 9 Administrator Reference Manual</citetitle>,
8bda0627eb2aca9e678c1303a0423d33069388dfwrowe </refsect1>
e36ef0d081aa59867688bcbb3da65952ec16fae3rbb <para><corpauthor>Internet Systems Consortium</corpauthor>
e36ef0d081aa59867688bcbb3da65952ec16fae3rbb </refsect1>
e36ef0d081aa59867688bcbb3da65952ec16fae3rbb - Local variables:
e36ef0d081aa59867688bcbb3da65952ec16fae3rbb - mode: sgml