dnssec-signzone.docbook revision ba751492fcc4f161a18b983d4f018a1a52938cb9
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
22be030b50b0aeab5c869507f34863ba1cec5bd3Tinderbox User "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
bef75d63d74f58abc0f834ed271526672777ba29Automatic Updater [<!ENTITY mdash "—">]>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - Copyright (C) 2004-2009, 2011-2013 Internet Systems Consortium, Inc. ("ISC")
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - Copyright (C) 2000-2003 Internet Software Consortium.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - Permission to use, copy, modify, and/or distribute this software for any
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - purpose with or without fee is hereby granted, provided that the above
bef75d63d74f58abc0f834ed271526672777ba29Automatic Updater - copyright notice and this permission notice appear in all copies.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews - PERFORMANCE OF THIS SOFTWARE.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews<!-- $Id: dnssec-signzone.docbook,v 1.52 2011/12/22 07:32:40 each Exp $ -->
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <refentryinfo>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews </refentryinfo>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <refentrytitle><application>dnssec-signzone</application></refentrytitle>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <refname><application>dnssec-signzone</application></refname>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <refpurpose>DNSSEC zone signing tool</refpurpose>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User </refnamediv>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <holder>Internet Software Consortium.</holder>
481870b95fee976541f4fe455c0ef2dbeab3ec7aTinderbox User <refsynopsisdiv>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <cmdsynopsis>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
e839bf134fb138920d4833cf05cb8b8906787a8dAutomatic Updater <arg><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <arg><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-k <replaceable class="parameter">key</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-L <replaceable class="parameter">serial</replaceable></option></arg>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
795a316ec568b2470aab18b9481443966047652eAutomatic Updater <arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <arg><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <arg><option>-X <replaceable class="parameter">extended end-time</replaceable></option></arg>
6478b87fd23bcd3ab74c25b261021fe19a239c4fTinderbox User <arg><option>-3 <replaceable class="parameter">salt</replaceable></option></arg>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <arg><option>-H <replaceable class="parameter">iterations</replaceable></option></arg>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User </cmdsynopsis>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User </refsynopsisdiv>
481870b95fee976541f4fe455c0ef2dbeab3ec7aTinderbox User signs a zone. It generates
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User NSEC and RRSIG records and produces a signed version of the
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews zone. The security status of delegations from the signed zone
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User (that is, whether the child zones are secure or not) is
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User determined by the presence or absence of a
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <filename>keyset</filename> file for each child zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <variablelist>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <varlistentry>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User Verify all generated signatures.
6f1205897504b8f50b1785975482c995888dd630Tinderbox User </varlistentry>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <varlistentry>
e62b9c9ce6413fb183c8116381e75dcd07ca5517Tinderbox User <term>-c <replaceable class="parameter">class</replaceable></term>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User Specifies the DNS class of the zone.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews </varlistentry>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <varlistentry>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User Compatibility mode: Generate a
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <filename>keyset-<replaceable>zonename</replaceable></filename>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews file in addition to
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <filename>dsset-<replaceable>zonename</replaceable></filename>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews when signing a zone, for use by older versions of
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User </varlistentry>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <varlistentry>
b27ce68bae92006e2ad7a9b75602c6385e529c3bAutomatic Updater <term>-d <replaceable class="parameter">directory</replaceable></term>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <filename>keyset-</filename> files in <option>directory</option>.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews </varlistentry>
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <varlistentry>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews Output only those record types automatically managed by
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User <command>dnssec-signzone</command>, i.e. RRSIG, NSEC,
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User NSEC3 and NSEC3PARAM records. If smart signing
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User (<option>-S</option>) is used, DNSKEY records are also
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User included. The resulting file can be included in the original
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User zone file with <command>$INCLUDE</command>. This option
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews cannot be combined with <option>-O raw</option>,
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <option>-O map</option>, or serial number updating.
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews </varlistentry>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <varlistentry>
582f8b9a8d170a80ef67475bddb8ad5cf7cd7cadMark Andrews <term>-E <replaceable class="parameter">engine</replaceable></term>
signatures on other records; e.g., when the private component
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
Kexample.com.+003+17247