dnssec-signzone.docbook revision 0bbe3273a224aa07b6af4165a26fd26d6f30c0ad
6a6838f97363c7f3abe47e1fb116be2593bc53a5Mark Andrews<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
6a6838f97363c7f3abe47e1fb116be2593bc53a5Mark Andrews "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
6a6838f97363c7f3abe47e1fb116be2593bc53a5Mark Andrews [<!ENTITY mdash "&#8212;">]>
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrews<!--
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrews - Copyright (C) 2004-2009, 2011-2013 Internet Systems Consortium, Inc. ("ISC")
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrews - Copyright (C) 2000-2003 Internet Software Consortium.
ac5ed748602c890d596bed07b0b23b8b5f42b2f6Mark Andrews -
89cf81b4625c574f60c21e0dce12b150f3c5583cMark Andrews - Permission to use, copy, modify, and/or distribute this software for any
89cf81b4625c574f60c21e0dce12b150f3c5583cMark Andrews - purpose with or without fee is hereby granted, provided that the above
89cf81b4625c574f60c21e0dce12b150f3c5583cMark Andrews - copyright notice and this permission notice appear in all copies.
2064e46209f35d2afad526622d975647f9c2098bMark Andrews -
2064e46209f35d2afad526622d975647f9c2098bMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
2064e46209f35d2afad526622d975647f9c2098bMark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
71ec6d09406771c0ad546d2d475a7f16c0198844Mark Andrews - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
71ec6d09406771c0ad546d2d475a7f16c0198844Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
71ec6d09406771c0ad546d2d475a7f16c0198844Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
71ec6d09406771c0ad546d2d475a7f16c0198844Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
a920fb9dc2ff16f32dd73e53469d0febcdcc6c11Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
a920fb9dc2ff16f32dd73e53469d0febcdcc6c11Mark Andrews-->
a920fb9dc2ff16f32dd73e53469d0febcdcc6c11Mark Andrews
3c13af375900ffe79af4926953799e6123c9d698Mark Andrews<!-- $Id: dnssec-signzone.docbook,v 1.52 2011/12/22 07:32:40 each Exp $ -->
3c13af375900ffe79af4926953799e6123c9d698Mark Andrews<refentry id="man.dnssec-signzone">
3c13af375900ffe79af4926953799e6123c9d698Mark Andrews <refentryinfo>
d734818278966c45af997c7242e8cccd7a91a0b3Mark Andrews <date>June 05, 2009</date>
d734818278966c45af997c7242e8cccd7a91a0b3Mark Andrews </refentryinfo>
d734818278966c45af997c7242e8cccd7a91a0b3Mark Andrews
63e1ac1e0915dd1089493d6d092d39a3da817e59Mark Andrews <refmeta>
63e1ac1e0915dd1089493d6d092d39a3da817e59Mark Andrews <refentrytitle><application>dnssec-signzone</application></refentrytitle>
63e1ac1e0915dd1089493d6d092d39a3da817e59Mark Andrews <manvolnum>8</manvolnum>
63e1ac1e0915dd1089493d6d092d39a3da817e59Mark Andrews <refmiscinfo>BIND9</refmiscinfo>
89119e3cafff373426858f6cec7c09539f53e209Mark Andrews </refmeta>
89119e3cafff373426858f6cec7c09539f53e209Mark Andrews
89119e3cafff373426858f6cec7c09539f53e209Mark Andrews <refnamediv>
33399d6a143403bc4a9ccb9307af43ef04ab7633Mark Andrews <refname><application>dnssec-signzone</application></refname>
33399d6a143403bc4a9ccb9307af43ef04ab7633Mark Andrews <refpurpose>DNSSEC zone signing tool</refpurpose>
33399d6a143403bc4a9ccb9307af43ef04ab7633Mark Andrews </refnamediv>
ef117da20559f2a65f46ed9eb40deab5026cbd66Mark Andrews
ef117da20559f2a65f46ed9eb40deab5026cbd66Mark Andrews <docinfo>
ef117da20559f2a65f46ed9eb40deab5026cbd66Mark Andrews <copyright>
ba5c73b383b08326ab6b5ad2d7ca43e117e212f1Mark Andrews <year>2004</year>
ba5c73b383b08326ab6b5ad2d7ca43e117e212f1Mark Andrews <year>2005</year>
ba5c73b383b08326ab6b5ad2d7ca43e117e212f1Mark Andrews <year>2006</year>
bf59efcf0ed41186a5f9c1ca61da15a3c99b46f3Mark Andrews <year>2007</year>
bf59efcf0ed41186a5f9c1ca61da15a3c99b46f3Mark Andrews <year>2008</year>
bf59efcf0ed41186a5f9c1ca61da15a3c99b46f3Mark Andrews <year>2009</year>
cac2181160bdb3ccc89e3560addae5e38d4c05e3Evan Hunt <year>2011</year>
cac2181160bdb3ccc89e3560addae5e38d4c05e3Evan Hunt <year>2012</year>
faefeaddb39e693ea6cbcb81f2e5dbded21ced93Evan Hunt <year>2013</year>
faefeaddb39e693ea6cbcb81f2e5dbded21ced93Evan Hunt <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt </copyright>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <copyright>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <year>2000</year>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <year>2001</year>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <year>2002</year>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <year>2003</year>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt <holder>Internet Software Consortium.</holder>
b8a9632333a92d73a503afe1aaa7990016c8bee9Evan Hunt </copyright>
f5bb5eb7f6640af4a94e666bf1d7f84a6a7f1f23Mark Andrews </docinfo>
f5bb5eb7f6640af4a94e666bf1d7f84a6a7f1f23Mark Andrews
f5bb5eb7f6640af4a94e666bf1d7f84a6a7f1f23Mark Andrews <refsynopsisdiv>
a0d411c05f12c36b298d811af3b4f2c9f08e86d4Mark Andrews <cmdsynopsis>
a0d411c05f12c36b298d811af3b4f2c9f08e86d4Mark Andrews <command>dnssec-signzone</command>
a0d411c05f12c36b298d811af3b4f2c9f08e86d4Mark Andrews <arg><option>-a</option></arg>
a0d411c05f12c36b298d811af3b4f2c9f08e86d4Mark Andrews <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
42782931073786f98d3d0a617351db40066949a4Mukund Sivaraman <arg><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
42782931073786f98d3d0a617351db40066949a4Mukund Sivaraman <arg><option>-D</option></arg>
42782931073786f98d3d0a617351db40066949a4Mukund Sivaraman <arg><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
c1d33c159bf81d6faf9948ac9a6f307ca52284afEvan Hunt <arg><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
c1d33c159bf81d6faf9948ac9a6f307ca52284afEvan Hunt <arg><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
c1d33c159bf81d6faf9948ac9a6f307ca52284afEvan Hunt <arg><option>-g</option></arg>
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt <arg><option>-h</option></arg>
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt <arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt <arg><option>-k <replaceable class="parameter">key</replaceable></option></arg>
06e0d6bb126e9986f29036e671b59f48b1d2efbcEvan Hunt <arg><option>-L <replaceable class="parameter">serial</replaceable></option></arg>
8d8f9f7f86a33a155dd74b9b2c1317afca555d54Evan Hunt <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
8d8f9f7f86a33a155dd74b9b2c1317afca555d54Evan Hunt <arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
8d8f9f7f86a33a155dd74b9b2c1317afca555d54Evan Hunt <arg><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
7c9d11b654028f9901183c076b37a5494635f447Evan Hunt <arg><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
7c9d11b654028f9901183c076b37a5494635f447Evan Hunt <arg><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
7c9d11b654028f9901183c076b37a5494635f447Evan Hunt <arg><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
20dec973da306d5b0776c9d3b598fdbd3a59a28eMark Andrews <arg><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
20dec973da306d5b0776c9d3b598fdbd3a59a28eMark Andrews <arg><option>-P</option></arg>
20dec973da306d5b0776c9d3b598fdbd3a59a28eMark Andrews <arg><option>-p</option></arg>
3b187cad7a1754e098ab9dabfcb44c8b437fb589Mark Andrews <arg><option>-R</option></arg>
3b187cad7a1754e098ab9dabfcb44c8b437fb589Mark Andrews <arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
b16d99bac1d100735224ab3eaa84632537ff21b5Mark Andrews <arg><option>-S</option></arg>
b16d99bac1d100735224ab3eaa84632537ff21b5Mark Andrews <arg><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
79d27f505a67ee1fb5cf104cbe7b1ead67d252b4Mukund Sivaraman <arg><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
79d27f505a67ee1fb5cf104cbe7b1ead67d252b4Mukund Sivaraman <arg><option>-t</option></arg>
79d27f505a67ee1fb5cf104cbe7b1ead67d252b4Mukund Sivaraman <arg><option>-u</option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-X <replaceable class="parameter">extended end-time</replaceable></option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-x</option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-z</option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-3 <replaceable class="parameter">salt</replaceable></option></arg>
84dc4b3e7eea3e9c8fafa5f4fd632a51ee8b356fMukund Sivaraman <arg><option>-H <replaceable class="parameter">iterations</replaceable></option></arg>
93d4128dcd54c152cf97b2c36caba8f3c8de3280Mark Andrews <arg><option>-A</option></arg>
93d4128dcd54c152cf97b2c36caba8f3c8de3280Mark Andrews <arg choice="req">zonefile</arg>
93d4128dcd54c152cf97b2c36caba8f3c8de3280Mark Andrews <arg rep="repeat">key</arg>
50a745417461a4c007248202bb3a8bf7be426813Mark Andrews </cmdsynopsis>
50a745417461a4c007248202bb3a8bf7be426813Mark Andrews </refsynopsisdiv>
50a745417461a4c007248202bb3a8bf7be426813Mark Andrews
50a745417461a4c007248202bb3a8bf7be426813Mark Andrews <refsect1>
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt <title>DESCRIPTION</title>
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt <para><command>dnssec-signzone</command>
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt signs a zone. It generates
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt NSEC and RRSIG records and produces a signed version of the
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt zone. The security status of delegations from the signed zone
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt (that is, whether the child zones are secure or not) is
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt determined by the presence or absence of a
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt <filename>keyset</filename> file for each child zone.
0cfb24736841b3e98bb25853229a0efabab88bddEvan Hunt </para>
fa6308bd57f716732ba70bbafc1d09e861e4acc1Mark Andrews </refsect1>
fa6308bd57f716732ba70bbafc1d09e861e4acc1Mark Andrews
fa6308bd57f716732ba70bbafc1d09e861e4acc1Mark Andrews <refsect1>
a4d76e3f0ba6f1fc2ba4b324f318e909b83bc860Evan Hunt <title>OPTIONS</title>
a4d76e3f0ba6f1fc2ba4b324f318e909b83bc860Evan Hunt
a4d76e3f0ba6f1fc2ba4b324f318e909b83bc860Evan Hunt <variablelist>
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrews <varlistentry>
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrews <term>-a</term>
3d751891410f9892ca1c1deba2f7d8556ae91b0cMark Andrews <listitem>
800d25b8482c52487b4dab53cb10fa74061f1e94Mark Andrews <para>
800d25b8482c52487b4dab53cb10fa74061f1e94Mark Andrews Verify all generated signatures.
800d25b8482c52487b4dab53cb10fa74061f1e94Mark Andrews </para>
800d25b8482c52487b4dab53cb10fa74061f1e94Mark Andrews </listitem>
9b819daddf8f4a5bd42276ee91bf9686d42f3ceeMark Andrews </varlistentry>
9b819daddf8f4a5bd42276ee91bf9686d42f3ceeMark Andrews
9b819daddf8f4a5bd42276ee91bf9686d42f3ceeMark Andrews <varlistentry>
586d94eb740587975d5348b22a5fb8440d95925dMark Andrews <term>-c <replaceable class="parameter">class</replaceable></term>
f7ae6c8fdd2cd5e276251647e6852cccfc92847bMark Andrews <listitem>
f7ae6c8fdd2cd5e276251647e6852cccfc92847bMark Andrews <para>
586d94eb740587975d5348b22a5fb8440d95925dMark Andrews Specifies the DNS class of the zone.
a569e1b3213668bc704194367ea12c23456ad1d2Mark Andrews </para>
a569e1b3213668bc704194367ea12c23456ad1d2Mark Andrews </listitem>
a569e1b3213668bc704194367ea12c23456ad1d2Mark Andrews </varlistentry>
a569e1b3213668bc704194367ea12c23456ad1d2Mark Andrews
c6f7d2b5f1378e3d61770766ee9fdd922471eb2fMark Andrews <varlistentry>
c6f7d2b5f1378e3d61770766ee9fdd922471eb2fMark Andrews <term>-C</term>
603a78708343f063b44affb882ef93bb19a5142aMark Andrews <listitem>
603a78708343f063b44affb882ef93bb19a5142aMark Andrews <para>
603a78708343f063b44affb882ef93bb19a5142aMark Andrews Compatibility mode: Generate a
ba586e9568364eb2da871f5fb2b71716f7c31865Mark Andrews <filename>keyset-<replaceable>zonename</replaceable></filename>
ba586e9568364eb2da871f5fb2b71716f7c31865Mark Andrews file in addition to
ba586e9568364eb2da871f5fb2b71716f7c31865Mark Andrews <filename>dsset-<replaceable>zonename</replaceable></filename>
a0f91e910bd9af006a65e555ec4082864ca1eb8dMark Andrews when signing a zone, for use by older versions of
570216f5a373cdaaa2eb2d9b5990150dd5a7b41bEvan Hunt <command>dnssec-signzone</command>.
a0f91e910bd9af006a65e555ec4082864ca1eb8dMark Andrews </para>
a0f91e910bd9af006a65e555ec4082864ca1eb8dMark Andrews </listitem>
0fe07891819138ad6e1de45f279cff940d170542Mark Andrews </varlistentry>
0fe07891819138ad6e1de45f279cff940d170542Mark Andrews
0fe07891819138ad6e1de45f279cff940d170542Mark Andrews <varlistentry>
ea58c563bccc2a8dc20886c99c7c3334a971b6d3Evan Hunt <term>-d <replaceable class="parameter">directory</replaceable></term>
d319beb9d0b08db8b7f9789d916a02a56976b9b9Tinderbox User <listitem>
ea58c563bccc2a8dc20886c99c7c3334a971b6d3Evan Hunt <para>
a6d48ae49345c1995c7ac7c0628bf5f9eac0719aJeremy C. Reed Look for <filename>dsset-</filename> or
27b09ceb12ec95de461bd2780615d4064ccb1419Mark Andrews <filename>keyset-</filename> files in <option>directory</option>.
27b09ceb12ec95de461bd2780615d4064ccb1419Mark Andrews </para>
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt </listitem>
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt </varlistentry>
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt <varlistentry>
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt <term>-D</term>
896f49f8bdee644cd8d10e320ea3084ca3f74e2aEvan Hunt <listitem>
6fa84a3e255ef9e6233f0a8d134fc6d273f04599Evan Hunt <para>
6fa84a3e255ef9e6233f0a8d134fc6d273f04599Evan Hunt Output only those record types automatically managed by
7f7d32d1e4023a4a74432e45dd4105ea0528c3cfEvan Hunt <command>dnssec-signzone</command>, i.e. RRSIG, NSEC,
104f0e51ac7f472e69d53e4900fe121b7dc78537Tinderbox User NSEC3 and NSEC3PARAM records. If smart signing
6fa84a3e255ef9e6233f0a8d134fc6d273f04599Evan Hunt (<option>-S</option>) is used, DNSKEY records are also
ca84a056bdb492e8894c70fd7bf6a885df03039fMark Andrews included. The resulting file can be included in the original
01f881c1c5683054ee3366929eae6f811777ce46Mark Andrews zone file with <command>$INCLUDE</command>. This option
01f881c1c5683054ee3366929eae6f811777ce46Mark Andrews cannot be combined with <option>-O raw</option>,
ca84a056bdb492e8894c70fd7bf6a885df03039fMark Andrews <option>-O map</option>, or serial number updating.
ca84a056bdb492e8894c70fd7bf6a885df03039fMark Andrews </para>
a14fe8522977d391096942aae5250f00ca32d2d4Mark Andrews </listitem>
a14fe8522977d391096942aae5250f00ca32d2d4Mark Andrews </varlistentry>
a14fe8522977d391096942aae5250f00ca32d2d4Mark Andrews
5a8edcafd13fc63a066e8e42e0f95cdbf9606414Mark Andrews <varlistentry>
5a8edcafd13fc63a066e8e42e0f95cdbf9606414Mark Andrews <term>-E <replaceable class="parameter">engine</replaceable></term>
5a8edcafd13fc63a066e8e42e0f95cdbf9606414Mark Andrews <listitem>
05816676bb82a5657a741ef4d378c7fb83912cfcMark Andrews <para>
05816676bb82a5657a741ef4d378c7fb83912cfcMark Andrews Uses a crypto hardware (OpenSSL engine) for the crypto operations
05816676bb82a5657a741ef4d378c7fb83912cfcMark Andrews it supports, for instance signing with private keys from
29225772176ec580b2c903928a5c18e2e24889d0Mark Andrews a secure key store. When compiled with PKCS#11 support
29225772176ec580b2c903928a5c18e2e24889d0Mark Andrews it defaults to pkcs11; the empty name resets it to no engine.
1b513b6120e6f445960149b8f057aea19e1f5fe6Francis Dupont </para>
761f60fc356c9987258cd10b4aa216c6296d922bFrancis Dupont </listitem>
8114b0be01e98526f91da33f9685ac7014fcc598Mark Andrews </varlistentry>
761f60fc356c9987258cd10b4aa216c6296d922bFrancis Dupont
0e338b60cdb2cf7cedb4fc17f6a14b518d1245c8Mark Andrews <varlistentry>
0e338b60cdb2cf7cedb4fc17f6a14b518d1245c8Mark Andrews <term>-g</term>
0e338b60cdb2cf7cedb4fc17f6a14b518d1245c8Mark Andrews <listitem>
2c172a42b39da5913fc6b2c0d3ce987c206991faMark Andrews <para>
2c172a42b39da5913fc6b2c0d3ce987c206991faMark Andrews Generate DS records for child zones from
faa01edd13613c077c3cb663c36f36bd527d1a4bMark Andrews <filename>dsset-</filename> or <filename>keyset-</filename>
faa01edd13613c077c3cb663c36f36bd527d1a4bMark Andrews file. Existing DS records will be removed.
faa01edd13613c077c3cb663c36f36bd527d1a4bMark Andrews </para>
1ea6e09c376b1351c614474a88675b1a9bda6571Evan Hunt </listitem>
1ea6e09c376b1351c614474a88675b1a9bda6571Evan Hunt </varlistentry>
1ea6e09c376b1351c614474a88675b1a9bda6571Evan Hunt
60988462e5d6db53205851d056e3482a29239be9Evan Hunt <varlistentry>
60988462e5d6db53205851d056e3482a29239be9Evan Hunt <term>-K <replaceable class="parameter">directory</replaceable></term>
60988462e5d6db53205851d056e3482a29239be9Evan Hunt <listitem>
cd07e4d038fda6f9bacecb3067cc6fa43a67fc0aMark Andrews <para>
cd07e4d038fda6f9bacecb3067cc6fa43a67fc0aMark Andrews Key repository: Specify a directory to search for DNSSEC keys.
b36fc8294e1328912b940899d436c60986c92435Mark Andrews If not specified, defaults to the current directory.
b36fc8294e1328912b940899d436c60986c92435Mark Andrews </para>
fe148bca7ea6612bb7e931fdcd2e66c32d2d2a9aMark Andrews </listitem>
b36fc8294e1328912b940899d436c60986c92435Mark Andrews </varlistentry>
dd820d8fd2714ee1ae53ff0c7f6973250048f2d2Mark Andrews
dd820d8fd2714ee1ae53ff0c7f6973250048f2d2Mark Andrews <varlistentry>
c0c4512020c0a4a9e5b087cb8cad1cd68fb3f52eEvan Hunt <term>-k <replaceable class="parameter">key</replaceable></term>
c0de0cd8d88485aba260a08dccca76f83bdf9538Tinderbox User <listitem>
c0c4512020c0a4a9e5b087cb8cad1cd68fb3f52eEvan Hunt <para>
5d739300d12363f36ffa72836d2c10ff8c791b12Mark Andrews Treat specified key as a key signing key ignoring any
5d739300d12363f36ffa72836d2c10ff8c791b12Mark Andrews key flags. This option may be specified multiple times.
5d739300d12363f36ffa72836d2c10ff8c791b12Mark Andrews </para>
5d739300d12363f36ffa72836d2c10ff8c791b12Mark Andrews </listitem>
6f78147f569c9f505ef048c2f9e4e1b5ef2a27e7Mark Andrews </varlistentry>
87344c2cb3d4b413941d514a078f4098bcb816e9Mark Andrews
87344c2cb3d4b413941d514a078f4098bcb816e9Mark Andrews <varlistentry>
44613d4d868ed5e73a1132280880f0699af56733Evan Hunt <term>-l <replaceable class="parameter">domain</replaceable></term>
44613d4d868ed5e73a1132280880f0699af56733Evan Hunt <listitem>
44613d4d868ed5e73a1132280880f0699af56733Evan Hunt <para>
44613d4d868ed5e73a1132280880f0699af56733Evan Hunt Generate a DLV set in addition to the key (DNSKEY) and DS sets.
44613d4d868ed5e73a1132280880f0699af56733Evan Hunt The domain is appended to the name of the records.
2b78610512f208a6a35eb0976d039c2001cba7e6Evan Hunt </para>
2b78610512f208a6a35eb0976d039c2001cba7e6Evan Hunt </listitem>
2b78610512f208a6a35eb0976d039c2001cba7e6Evan Hunt </varlistentry>
0dc0b029e9aecc6e2139109091ea68cc6aff7081Evan Hunt
0dc0b029e9aecc6e2139109091ea68cc6aff7081Evan Hunt <varlistentry>
0dc0b029e9aecc6e2139109091ea68cc6aff7081Evan Hunt <term>-s <replaceable class="parameter">start-time</replaceable></term>
0dc0b029e9aecc6e2139109091ea68cc6aff7081Evan Hunt <listitem>
cd750f6e7449678173e8cfe080ae0bf3dcb424cfEvan Hunt <para>
cd750f6e7449678173e8cfe080ae0bf3dcb424cfEvan Hunt Specify the date and time when the generated RRSIG records
cd750f6e7449678173e8cfe080ae0bf3dcb424cfEvan Hunt become valid. This can be either an absolute or relative
cd750f6e7449678173e8cfe080ae0bf3dcb424cfEvan Hunt time. An absolute start time is indicated by a number
cd750f6e7449678173e8cfe080ae0bf3dcb424cfEvan Hunt in YYYYMMDDHHMMSS notation; 20000530144500 denotes
5cef2421bde74ef8f789c9c83c1219553060ce16Mark Andrews 14:45:00 UTC on May 30th, 2000. A relative start time is
b4ba66ba1e36a6d8236d20be55273ce663819d69Evan Hunt indicated by +N, which is N seconds from the current time.
b4ba66ba1e36a6d8236d20be55273ce663819d69Evan Hunt If no <option>start-time</option> is specified, the current
b4ba66ba1e36a6d8236d20be55273ce663819d69Evan Hunt time minus 1 hour (to allow for clock skew) is used.
5cef2421bde74ef8f789c9c83c1219553060ce16Mark Andrews </para>
5cef2421bde74ef8f789c9c83c1219553060ce16Mark Andrews </listitem>
6bc767b003ed72f831dff7bb1b8f1855de281eb6Mark Andrews </varlistentry>
3e5743068c95036324c24efa47b36ab0f7916d47Evan Hunt
3e5743068c95036324c24efa47b36ab0f7916d47Evan Hunt <varlistentry>
c11e46110b2b6236c68d89d4ea557c1d35e5d271Mark Andrews <term>-e <replaceable class="parameter">end-time</replaceable></term>
c11e46110b2b6236c68d89d4ea557c1d35e5d271Mark Andrews <listitem>
c11e46110b2b6236c68d89d4ea557c1d35e5d271Mark Andrews <para>
e01fbe2a45f9641968264a3bdf76d290e20521d7Evan Hunt Specify the date and time when the generated RRSIG records
e01fbe2a45f9641968264a3bdf76d290e20521d7Evan Hunt expire. As with <option>start-time</option>, an absolute
e01fbe2a45f9641968264a3bdf76d290e20521d7Evan Hunt time is indicated in YYYYMMDDHHMMSS notation. A time relative
e01fbe2a45f9641968264a3bdf76d290e20521d7Evan Hunt to the start time is indicated with +N, which is N seconds from
76884179fd3ba491db80a285c752671025f74730Mark Andrews the start time. A time relative to the current time is
76884179fd3ba491db80a285c752671025f74730Mark Andrews indicated with now+N. If no <option>end-time</option> is
eb1a7730f013e9a16d709c9ee8f41d73cde3680eEvan Hunt specified, 30 days from the start time is used as a default.
eb1a7730f013e9a16d709c9ee8f41d73cde3680eEvan Hunt <option>end-time</option> must be later than
eb1a7730f013e9a16d709c9ee8f41d73cde3680eEvan Hunt <option>start-time</option>.
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt </para>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt </listitem>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt </varlistentry>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt <varlistentry>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt <term>-X <replaceable class="parameter">extended end-time</replaceable></term>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt <listitem>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt <para>
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt Specify the date and time when the generated RRSIG records
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt for the DNSKEY RRset will expire. This is to be used in cases
aefb3e308ba01ad47a3d3aaadf77a5edd4261cb9Evan Hunt when the DNSKEY signatures need to persist longer than
36e5ac00333d89001f0c518a7d381d16c38d0402Mark Andrews signatures on other records; e.g., when the private component
36e5ac00333d89001f0c518a7d381d16c38d0402Mark Andrews of the KSK is kept offline and the KSK signature is to be
36e5ac00333d89001f0c518a7d381d16c38d0402Mark Andrews refreshed manually.
36e5ac00333d89001f0c518a7d381d16c38d0402Mark Andrews </para>
37f7c4c673622e984a41570fda42c1a678622fa4Tinderbox User <para>
e916c4f840e6f05c1137a2653b4ef70a1056bf74Mark Andrews As with <option>start-time</option>, an absolute
e916c4f840e6f05c1137a2653b4ef70a1056bf74Mark Andrews time is indicated in YYYYMMDDHHMMSS notation. A time relative
e916c4f840e6f05c1137a2653b4ef70a1056bf74Mark Andrews to the start time is indicated with +N, which is N seconds from
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews the start time. A time relative to the current time is
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews indicated with now+N. If no <option>extended end-time</option> is
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews specified, the value of <option>end-time</option> is used as
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews the default. (<option>end-time</option>, in turn, defaults to
1a9932dde111e05b4b9177c1146695817c3a20d2Evan Hunt 30 days from the start time.) <option>extended end-time</option>
1a9932dde111e05b4b9177c1146695817c3a20d2Evan Hunt must be later than <option>start-time</option>.
1a9932dde111e05b4b9177c1146695817c3a20d2Evan Hunt </para>
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews </listitem>
471f2b71d89897204af3f2ab00a010e4327e44f9Mark Andrews </varlistentry>
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt <varlistentry>
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt <term>-f <replaceable class="parameter">output-file</replaceable></term>
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt <listitem>
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt <para>
ec3b216506b715f10e0b653afc20068ce8c5aa79Evan Hunt The name of the output file containing the signed zone. The
4e7973990c2aaec391cf307a7e60583331568e01Evan Hunt default is to append <filename>.signed</filename> to
4e7973990c2aaec391cf307a7e60583331568e01Evan Hunt the input filename. If <option>output-file</option> is
4e7973990c2aaec391cf307a7e60583331568e01Evan Hunt set to <literal>"-"</literal>, then the signed zone is
4e7973990c2aaec391cf307a7e60583331568e01Evan Hunt written to the standard output, with a default output
a6d48ae49345c1995c7ac7c0628bf5f9eac0719aJeremy C. Reed format of "full".
e560fbdf77b08ff23ab71b107f022829bcd552dbMark Andrews </para>
e560fbdf77b08ff23ab71b107f022829bcd552dbMark Andrews </listitem>
7318bbc26262a66a0d740ceefed769961ef7e476Evan Hunt </varlistentry>
7318bbc26262a66a0d740ceefed769961ef7e476Evan Hunt
7318bbc26262a66a0d740ceefed769961ef7e476Evan Hunt <varlistentry>
7318bbc26262a66a0d740ceefed769961ef7e476Evan Hunt <term>-h</term>
469bbe0f973bf33e20d6011748cb68fab8a9a12dMark Andrews <listitem>
469bbe0f973bf33e20d6011748cb68fab8a9a12dMark Andrews <para>
469bbe0f973bf33e20d6011748cb68fab8a9a12dMark Andrews Prints a short summary of the options and arguments to
fc84418f4a809e40f16cfb5b4f3834d735fca31fTinderbox User <command>dnssec-signzone</command>.
993cde8f0fe3e08283990cc9ff4a555b5e48ab91Mark Andrews </para>
2dc978b8a1563f6dd413a8a9456659ade00f9e9eEvan Hunt </listitem>
2dc978b8a1563f6dd413a8a9456659ade00f9e9eEvan Hunt </varlistentry>
a6d48ae49345c1995c7ac7c0628bf5f9eac0719aJeremy C. Reed
7dcb304dd0bfe5888593199e0a9a8d64b8f022adMark Andrews <varlistentry>
7dcb304dd0bfe5888593199e0a9a8d64b8f022adMark Andrews <term>-i <replaceable class="parameter">interval</replaceable></term>
92fe6db3e46016f4ce0d6e372c745469bba10b5eEvan Hunt <listitem>
92fe6db3e46016f4ce0d6e372c745469bba10b5eEvan Hunt <para>
7cd8e7915afba7064c18c4bf74ecce0627c61027Evan Hunt When a previously-signed zone is passed as input, records
7cd8e7915afba7064c18c4bf74ecce0627c61027Evan Hunt may be resigned. The <option>interval</option> option
7cd8e7915afba7064c18c4bf74ecce0627c61027Evan Hunt specifies the cycle interval as an offset from the current
f5df4974b7b5081c4778d5796127b4d6584e834eEvan Hunt time (in seconds). If a RRSIG record expires after the
f5df4974b7b5081c4778d5796127b4d6584e834eEvan Hunt cycle interval, it is retained. Otherwise, it is considered
102c454e783d3dd9dbb9ceb30ed28c983cafd546Mark Andrews to be expiring soon, and it will be replaced.
f45f40ec2814a5ff1ed443c968772a1b2e25c462Mark Andrews </para>
f45f40ec2814a5ff1ed443c968772a1b2e25c462Mark Andrews <para>
f45f40ec2814a5ff1ed443c968772a1b2e25c462Mark Andrews The default cycle interval is one quarter of the difference
f45f40ec2814a5ff1ed443c968772a1b2e25c462Mark Andrews between the signature end and start times. So if neither
38c3ed154a2e014dad359e852b08722defa118ebEvan Hunt <option>end-time</option> or <option>start-time</option>
baad8d9fd8dd054ce1edf350ff0c0f2038a1519eEvan Hunt are specified, <command>dnssec-signzone</command>
baad8d9fd8dd054ce1edf350ff0c0f2038a1519eEvan Hunt generates
baad8d9fd8dd054ce1edf350ff0c0f2038a1519eEvan Hunt signatures that are valid for 30 days, with a cycle
baad8d9fd8dd054ce1edf350ff0c0f2038a1519eEvan Hunt interval of 7.5 days. Therefore, if any existing RRSIG records
866606b9c712ac654689e02a0c12151eaa86fbc1Mark Andrews are due to expire in less than 7.5 days, they would be
866606b9c712ac654689e02a0c12151eaa86fbc1Mark Andrews replaced.
f0e9d6e905235482ff9b4be770ee35018fcd8234Evan Hunt </para>
f0e9d6e905235482ff9b4be770ee35018fcd8234Evan Hunt </listitem>
7ef5dc87b64d639cadfcce868428f9fb2a84fb92Evan Hunt </varlistentry>
7ef5dc87b64d639cadfcce868428f9fb2a84fb92Evan Hunt
7ef5dc87b64d639cadfcce868428f9fb2a84fb92Evan Hunt <varlistentry>
44fbdddcadd85a6e40ebc7b7834e08e156c681a1Evan Hunt <term>-I <replaceable class="parameter">input-format</replaceable></term>
44fbdddcadd85a6e40ebc7b7834e08e156c681a1Evan Hunt <listitem>
44fbdddcadd85a6e40ebc7b7834e08e156c681a1Evan Hunt <para>
0dfd942409fbd3ad1e9a06c887742f0c8760ffd7Mark Andrews The format of the input zone file.
0dfd942409fbd3ad1e9a06c887742f0c8760ffd7Mark Andrews Possible formats are <command>"text"</command> (default),
0dfd942409fbd3ad1e9a06c887742f0c8760ffd7Mark Andrews <command>"raw"</command>, and <command>"map"</command>.
568de8123acb1a94e2d7bfe9cc5eb5d099f6c1f5Mark Andrews This option is primarily intended to be used for dynamic
568de8123acb1a94e2d7bfe9cc5eb5d099f6c1f5Mark Andrews signed zones so that the dumped zone file in a non-text
51e6164fd6b47121040f79b6330edf6258418a0bMark Andrews format containing updates can be signed directly.
51e6164fd6b47121040f79b6330edf6258418a0bMark Andrews The use of this option does not make much sense for
ef9334d745a759b02821950230260c1941d066d3Mukund Sivaraman non-dynamic zones.
ef9334d745a759b02821950230260c1941d066d3Mukund Sivaraman </para>
ef9334d745a759b02821950230260c1941d066d3Mukund Sivaraman </listitem>
6ffa8fcf764121bbe3b9eb116ddade5778608375Mark Andrews </varlistentry>
6ffa8fcf764121bbe3b9eb116ddade5778608375Mark Andrews
bbd5c0ab33b7c76058a4b17bd1f9ce443aa90c7fEvan Hunt <varlistentry>
bbd5c0ab33b7c76058a4b17bd1f9ce443aa90c7fEvan Hunt <term>-j <replaceable class="parameter">jitter</replaceable></term>
bbd5c0ab33b7c76058a4b17bd1f9ce443aa90c7fEvan Hunt <listitem>
c73a7e127fd3d2b2d3257f67d7a0b94441797f3aMark Andrews <para>
c73a7e127fd3d2b2d3257f67d7a0b94441797f3aMark Andrews When signing a zone with a fixed signature lifetime, all
c73a7e127fd3d2b2d3257f67d7a0b94441797f3aMark Andrews RRSIG records issued at the time of signing expires
bad82a46c420eaa5ca62a319923472fba7e391f1Mark Andrews simultaneously. If the zone is incrementally signed, i.e.
bad82a46c420eaa5ca62a319923472fba7e391f1Mark Andrews a previously-signed zone is passed as input to the signer,
09ab38c151751b76b8043275422239463eb70cbdMark Andrews all expired signatures have to be regenerated at about the
09ab38c151751b76b8043275422239463eb70cbdMark Andrews same time. The <option>jitter</option> option specifies a
09ab38c151751b76b8043275422239463eb70cbdMark Andrews jitter window that will be used to randomize the signature
09ab38c151751b76b8043275422239463eb70cbdMark Andrews expire time, thus spreading incremental signature
adbb48b4a0c6216f96d8b40712f23da893444f1cMark Andrews regeneration over time.
adbb48b4a0c6216f96d8b40712f23da893444f1cMark Andrews </para>
61cfadb50e2ddce1073760e77880de73eb6e65daMark Andrews <para>
61cfadb50e2ddce1073760e77880de73eb6e65daMark Andrews Signature lifetime jitter also to some extent benefits
61cfadb50e2ddce1073760e77880de73eb6e65daMark Andrews validators and servers by spreading out cache expiration,
9896a01aebb4201459079f8926dcd8045514b73aEvan Hunt i.e. if large numbers of RRSIGs don't expire at the same time
9896a01aebb4201459079f8926dcd8045514b73aEvan Hunt from all caches there will be less congestion than if all
22e29471c784acd09619841926c4f765e36ac74aEvan Hunt validators need to refetch at mostly the same time.
22e29471c784acd09619841926c4f765e36ac74aEvan Hunt </para>
22e29471c784acd09619841926c4f765e36ac74aEvan Hunt </listitem>
22e29471c784acd09619841926c4f765e36ac74aEvan Hunt </varlistentry>
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt <varlistentry>
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt <term>-L <replaceable class="parameter">serial</replaceable></term>
9823d3d0fa2995a90f577a5801b1e5f7288a1facJeremy C. Reed <listitem>
acbb301e648b82fcc38b876a44403cf0fe539cc9Evan Hunt <para>
9823d3d0fa2995a90f577a5801b1e5f7288a1facJeremy C. Reed When writing a signed zone to "raw" or "map" format, set the
3911e7610f29dc664cbe8336f35c0652cd74652eMark Andrews "source serial" value in the header to the specified serial
3911e7610f29dc664cbe8336f35c0652cd74652eMark Andrews number. (This is expected to be used primarily for testing
89740699cd2191d9b84e67716c281b2dfeba5e56Evan Hunt purposes.)
89740699cd2191d9b84e67716c281b2dfeba5e56Evan Hunt </para>
89740699cd2191d9b84e67716c281b2dfeba5e56Evan Hunt </listitem>
89740699cd2191d9b84e67716c281b2dfeba5e56Evan Hunt </varlistentry>
89740699cd2191d9b84e67716c281b2dfeba5e56Evan Hunt
46bc64f4b1a0e84ab0397943453fe83a17baf2c4Evan Hunt <varlistentry>
46bc64f4b1a0e84ab0397943453fe83a17baf2c4Evan Hunt <term>-n <replaceable class="parameter">ncpus</replaceable></term>
46bc64f4b1a0e84ab0397943453fe83a17baf2c4Evan Hunt <listitem>
46bc64f4b1a0e84ab0397943453fe83a17baf2c4Evan Hunt <para>
46bc64f4b1a0e84ab0397943453fe83a17baf2c4Evan Hunt Specifies the number of threads to use. By default, one
1cf8e9c0b7e75fcd2bfd10367ff362c674972a0dMark Andrews thread is started for each detected CPU.
62258ada486dfe76afc3f0f3835d3a45d2d8105cEvan Hunt </para>
62258ada486dfe76afc3f0f3835d3a45d2d8105cEvan Hunt </listitem>
62258ada486dfe76afc3f0f3835d3a45d2d8105cEvan Hunt </varlistentry>
8cbf3b6fc35091abde426930f2eadb8f53476c98Evan Hunt
8cbf3b6fc35091abde426930f2eadb8f53476c98Evan Hunt <varlistentry>
8cbf3b6fc35091abde426930f2eadb8f53476c98Evan Hunt <term>-N <replaceable class="parameter">soa-serial-format</replaceable></term>
8cbf3b6fc35091abde426930f2eadb8f53476c98Evan Hunt <listitem>
8cbf3b6fc35091abde426930f2eadb8f53476c98Evan Hunt <para>
7bd455641455950eff7d21be652c8142b134d32fTinderbox User The SOA serial number format of the signed zone.
7b46a4aa418de3e1f2df63b9353b7148584afe64Evan Hunt Possible formats are <command>"keep"</command> (default),
7b46a4aa418de3e1f2df63b9353b7148584afe64Evan Hunt <command>"increment"</command> and
9ba2cef72dacb1dc1105415956e1c311ac25d02cEvan Hunt <command>"unixtime"</command>.
9ba2cef72dacb1dc1105415956e1c311ac25d02cEvan Hunt </para>
9ba2cef72dacb1dc1105415956e1c311ac25d02cEvan Hunt
78f79084fcfc40f1237c99e2d4325b24b750d012Evan Hunt <variablelist>
78f79084fcfc40f1237c99e2d4325b24b750d012Evan Hunt <varlistentry>
78f79084fcfc40f1237c99e2d4325b24b750d012Evan Hunt <term><command>"keep"</command></term>
a2fd1de97d9ff685697aadba7f67a450557b0a06Evan Hunt <listitem>
a2fd1de97d9ff685697aadba7f67a450557b0a06Evan Hunt <para>Do not modify the SOA serial number.</para>
a2fd1de97d9ff685697aadba7f67a450557b0a06Evan Hunt </listitem>
def8172275039dd667d2c54afa51af80fef9c2abEvan Hunt </varlistentry>
e7c0d42b11358f08e04316d31c67c23261dcdf36Evan Hunt
cc2a5156841ec6dfe1e90eed40c65fa8cdec246dTinderbox User <varlistentry>
e7c0d42b11358f08e04316d31c67c23261dcdf36Evan Hunt <term><command>"increment"</command></term>
d51456e4537729c2263303350abeff45379b1105Evan Hunt <listitem>
d51456e4537729c2263303350abeff45379b1105Evan Hunt <para>Increment the SOA serial number using RFC 1982
d51456e4537729c2263303350abeff45379b1105Evan Hunt arithmetics.</para>
d51456e4537729c2263303350abeff45379b1105Evan Hunt </listitem>
e69790ac0067c0034f57e070d513833550786a93Evan Hunt </varlistentry>
e69790ac0067c0034f57e070d513833550786a93Evan Hunt
e69790ac0067c0034f57e070d513833550786a93Evan Hunt <varlistentry>
67d01dcacb2051a03377c8ec5c0e36604c17aea5Evan Hunt <term><command>"unixtime"</command></term>
67d01dcacb2051a03377c8ec5c0e36604c17aea5Evan Hunt <listitem>
67d01dcacb2051a03377c8ec5c0e36604c17aea5Evan Hunt <para>Set the SOA serial number to the number of seconds
67d01dcacb2051a03377c8ec5c0e36604c17aea5Evan Hunt since epoch.</para>
6be12fa63b38fe7648811e042c9aad58cee2ead7Evan Hunt </listitem>
6be12fa63b38fe7648811e042c9aad58cee2ead7Evan Hunt </varlistentry>
6be12fa63b38fe7648811e042c9aad58cee2ead7Evan Hunt </variablelist>
6be12fa63b38fe7648811e042c9aad58cee2ead7Evan Hunt
262fea66373a062cac1a0e99b5a4675987bb61ffEvan Hunt </listitem>
262fea66373a062cac1a0e99b5a4675987bb61ffEvan Hunt </varlistentry>
262fea66373a062cac1a0e99b5a4675987bb61ffEvan Hunt
084ba95b083dc55fd10631ad43fa8fff48707648Evan Hunt <varlistentry>
084ba95b083dc55fd10631ad43fa8fff48707648Evan Hunt <term>-o <replaceable class="parameter">origin</replaceable></term>
084ba95b083dc55fd10631ad43fa8fff48707648Evan Hunt <listitem>
084ba95b083dc55fd10631ad43fa8fff48707648Evan Hunt <para>
3ef4b7383ab4310df48ee5143e361ab1cfa3c8e8Evan Hunt The zone origin. If not specified, the name of the zone file
3ef4b7383ab4310df48ee5143e361ab1cfa3c8e8Evan Hunt is assumed to be the origin.
3ef4b7383ab4310df48ee5143e361ab1cfa3c8e8Evan Hunt </para>
72aa3b2a4e33a1b9b3521fddce383002b7201ab7Evan Hunt </listitem>
72aa3b2a4e33a1b9b3521fddce383002b7201ab7Evan Hunt </varlistentry>
72aa3b2a4e33a1b9b3521fddce383002b7201ab7Evan Hunt
368aedf188d7c7782cae8a5ce2a978be47b5a764Evan Hunt <varlistentry>
368aedf188d7c7782cae8a5ce2a978be47b5a764Evan Hunt <term>-O <replaceable class="parameter">output-format</replaceable></term>
368aedf188d7c7782cae8a5ce2a978be47b5a764Evan Hunt <listitem>
e71905610c72f474a2943934a48f43121c79c939Evan Hunt <para>
e71905610c72f474a2943934a48f43121c79c939Evan Hunt The format of the output file containing the signed zone.
e71905610c72f474a2943934a48f43121c79c939Evan Hunt Possible formats are <command>"text"</command> (default),
1aced7b8702288f656ded594cd5bd7678bb4fe70Evan Hunt which is the standard textual representation of the zone;
1aced7b8702288f656ded594cd5bd7678bb4fe70Evan Hunt <command>"full"</command>, which is text output in a
1aced7b8702288f656ded594cd5bd7678bb4fe70Evan Hunt format suitable for processing by external scripts;
a60bf97f9f7dcde6f4ca6e8188245fb0866200dbEvan Hunt and <command>"map"</command>, <command>"raw"</command>,
a60bf97f9f7dcde6f4ca6e8188245fb0866200dbEvan Hunt and <command>"raw=N"</command>, which store the zone in
a60bf97f9f7dcde6f4ca6e8188245fb0866200dbEvan Hunt binary formats for rapid loading by <command>named</command>.
a60bf97f9f7dcde6f4ca6e8188245fb0866200dbEvan Hunt <command>"raw=N"</command> specifies the format version of
a60bf97f9f7dcde6f4ca6e8188245fb0866200dbEvan Hunt the raw zone file: if N is 0, the raw file can be read by
f79ee00c69259b9a27f9f0d12afa6c7b64005dedEvan Hunt any version of <command>named</command>; if N is 1, the file
f79ee00c69259b9a27f9f0d12afa6c7b64005dedEvan Hunt can be read by release 9.9.0 or higher; the default is 1.
f79ee00c69259b9a27f9f0d12afa6c7b64005dedEvan Hunt </para>
7fbbc9bfd34f47aab843de668d5f5ffbc53d6e45Mark Andrews </listitem>
7fbbc9bfd34f47aab843de668d5f5ffbc53d6e45Mark Andrews </varlistentry>
7fbbc9bfd34f47aab843de668d5f5ffbc53d6e45Mark Andrews
96c17c5ecb012028ad9d66f93a252994c6ed035cMark Andrews <varlistentry>
96c17c5ecb012028ad9d66f93a252994c6ed035cMark Andrews <term>-p</term>
96c17c5ecb012028ad9d66f93a252994c6ed035cMark Andrews <listitem>
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt <para>
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt Use pseudo-random data when signing the zone. This is faster,
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt but less secure, than using real random data. This option
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt may be useful when signing large zones or when the entropy
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt source is limited.
1eb5e1b4d7ea98dea07000edef15148d3d714b9dEvan Hunt </para>
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt </listitem>
3a01ded15da064de23124e5d1a89143eceec5523Evan Hunt </varlistentry>
3a01ded15da064de23124e5d1a89143eceec5523Evan Hunt
3a01ded15da064de23124e5d1a89143eceec5523Evan Hunt <varlistentry>
0072ae822d966550f7c0956ed22184ec20e98f34Mark Andrews <term>-P</term>
0072ae822d966550f7c0956ed22184ec20e98f34Mark Andrews <listitem>
0072ae822d966550f7c0956ed22184ec20e98f34Mark Andrews <para>
0072ae822d966550f7c0956ed22184ec20e98f34Mark Andrews Disable post sign verification tests.
9e39bafd2ef3e52719b5f16aec077c7885e7e1f1Mark Andrews </para>
9e39bafd2ef3e52719b5f16aec077c7885e7e1f1Mark Andrews <para>
02a5e3ed85cbfc099874bb34e5901537399b5e24Mark Andrews The post sign verification test ensures that for each algorithm
02a5e3ed85cbfc099874bb34e5901537399b5e24Mark Andrews in use there is at least one non revoked self signed KSK key,
02a5e3ed85cbfc099874bb34e5901537399b5e24Mark Andrews that all revoked KSK keys are self signed, and that all records
bce9696c7ac65792469b29ce0ad13564953b62caEvan Hunt in the zone are signed by the algorithm.
bce9696c7ac65792469b29ce0ad13564953b62caEvan Hunt This option skips these tests.
bce9696c7ac65792469b29ce0ad13564953b62caEvan Hunt </para>
bce9696c7ac65792469b29ce0ad13564953b62caEvan Hunt </listitem>
edd82b2ce275d513fb2799b90ec464f434880e87Mark Andrews </varlistentry>
edd82b2ce275d513fb2799b90ec464f434880e87Mark Andrews
86856f4f3069bb2d75851b56401ffde18f41198fMark Andrews <varlistentry>
86856f4f3069bb2d75851b56401ffde18f41198fMark Andrews <term>-Q</term>
86856f4f3069bb2d75851b56401ffde18f41198fMark Andrews <listitem>
86856f4f3069bb2d75851b56401ffde18f41198fMark Andrews <para>
83eecff731c1a049b12f01fb699fa15ab7ddac2eEvan Hunt Remove signatures from keys that are no longer active.
83eecff731c1a049b12f01fb699fa15ab7ddac2eEvan Hunt </para>
83eecff731c1a049b12f01fb699fa15ab7ddac2eEvan Hunt <para>
83eecff731c1a049b12f01fb699fa15ab7ddac2eEvan Hunt Normally, when a previously-signed zone is passed as input
16134801ce8fffbb6c42bb54d544c3397a45ad06Mark Andrews to the signer, and a DNSKEY record has been removed and
7da74ea46df30a7431441a3b8adf5134dab5067eJeremy C. Reed replaced with a new one, signatures from the old key
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt that are still within their validity period are retained.
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt This allows the zone to continue to validate with cached
16134801ce8fffbb6c42bb54d544c3397a45ad06Mark Andrews copies of the old DNSKEY RRset. The <option>-Q</option>
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt forces <command>dnssec-signzone</command> to remove
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt signatures from keys that are no longer active. This
16134801ce8fffbb6c42bb54d544c3397a45ad06Mark Andrews enables ZSK rollover using the procedure described in
d7b9756a214030b0022ce791b67b12fb7bceeea0Evan Hunt RFC 4641, section 4.2.1.1 ("Pre-Publish Key Rollover").
d7b9756a214030b0022ce791b67b12fb7bceeea0Evan Hunt </para>
4357e13a4bc2e175d73b20f9ef3e809b3e269ee4Evan Hunt </listitem>
4357e13a4bc2e175d73b20f9ef3e809b3e269ee4Evan Hunt </varlistentry>
d7b9756a214030b0022ce791b67b12fb7bceeea0Evan Hunt <varlistentry>
fd75aaa2b9816703fda5e8b2cd071a3ec7387a08Evan Hunt <term>-R</term>
7e2e41df676e1e19186242afd88a6794e37a9becMark Andrews <listitem>
7f5bdf7f4063c2fefb18900468d2c851f8de7816Evan Hunt <para>
7f5bdf7f4063c2fefb18900468d2c851f8de7816Evan Hunt Remove signatures from keys that are no longer published.
7f5bdf7f4063c2fefb18900468d2c851f8de7816Evan Hunt </para>
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt <para>
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt This option is similar to <option>-Q</option>, except it
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt forces <command>dnssec-signzone</command> to signatures from
1361e038900701e126213261c0a1178025ae5a72Tinderbox User keys that are no longer published. This enables ZSK rollover
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt using the procedure described in RFC 4641, section 4.2.1.2
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt ("Double Signature Zone Signing Key Rollover").
35f6a21f5f8114542c050bfcb484b39ce513d4bdEvan Hunt </para>
6a3fa181d1253db5191139e20231512eebaddeebEvan Hunt </listitem>
6a3fa181d1253db5191139e20231512eebaddeebEvan Hunt </varlistentry>
6a3fa181d1253db5191139e20231512eebaddeebEvan Hunt <varlistentry>
6a3fa181d1253db5191139e20231512eebaddeebEvan Hunt <term>-r <replaceable class="parameter">randomdev</replaceable></term>
6a3fa181d1253db5191139e20231512eebaddeebEvan Hunt <listitem>
b5f6271f4daf1e54501af2cb7dd278d7e8003d65Mark Andrews <para>
0a5927a14f055f5550c76c818119f4811984272cMark Andrews Specifies the source of randomness. If the operating
96a35905057eb2ba7d977460776b06ae0911c8a7Evan Hunt system does not provide a <filename>/dev/random</filename>
96a35905057eb2ba7d977460776b06ae0911c8a7Evan Hunt or equivalent device, the default source of randomness
1361e038900701e126213261c0a1178025ae5a72Tinderbox User is keyboard input. <filename>randomdev</filename>
b5f6271f4daf1e54501af2cb7dd278d7e8003d65Mark Andrews specifies
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt the name of a character device or file containing random
7da74ea46df30a7431441a3b8adf5134dab5067eJeremy C. Reed data to be used instead of the default. The special value
64584aa0980625f834fa148dc3c95ab714efe703Evan Hunt <filename>keyboard</filename> indicates that keyboard
b5f6271f4daf1e54501af2cb7dd278d7e8003d65Mark Andrews input should be used.
96a35905057eb2ba7d977460776b06ae0911c8a7Evan Hunt </para>
96a35905057eb2ba7d977460776b06ae0911c8a7Evan Hunt </listitem>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User </varlistentry>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User
1361e038900701e126213261c0a1178025ae5a72Tinderbox User <varlistentry>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User <term>-S</term>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User <listitem>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User <para>
1361e038900701e126213261c0a1178025ae5a72Tinderbox User Smart signing: Instructs <command>dnssec-signzone</command> to
1361e038900701e126213261c0a1178025ae5a72Tinderbox User search the key repository for keys that match the zone being
38eabfcee7a9f206c268834ab9cb6d3408a31380Mark Andrews signed, and to include them in the zone if appropriate.
38eabfcee7a9f206c268834ab9cb6d3408a31380Mark Andrews </para>
38eabfcee7a9f206c268834ab9cb6d3408a31380Mark Andrews <para>
38eabfcee7a9f206c268834ab9cb6d3408a31380Mark Andrews When a key is found, its timing metadata is examined to
38eabfcee7a9f206c268834ab9cb6d3408a31380Mark Andrews determine how it should be used, according to the following
7b9cb698dd07644762c675b5f57446467b4d5663Mark Andrews rules. Each successive rule takes priority over the prior
7b9cb698dd07644762c675b5f57446467b4d5663Mark Andrews ones:
51143259789034ac19e12984a8390b9f86ab368cMark Andrews </para>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt <variablelist>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt <varlistentry>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt <listitem>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt <para>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt If no timing metadata has been set for the key, the key is
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt published in the zone and used to sign the zone.
98922b2b2b024dcca25be7c220cf3b16b1e6c4b5Evan Hunt </para>
1d761cb453c76353deb8423c78e98d00c5f86ffaEvan Hunt </listitem>
14bf4702f37cc707ede64a097f7d4aa671265492Evan Hunt </varlistentry>
14bf4702f37cc707ede64a097f7d4aa671265492Evan Hunt
14bf4702f37cc707ede64a097f7d4aa671265492Evan Hunt <varlistentry>
31f6244cc25ab0f8937edc26dbb26ba4f6a01f19Evan Hunt <listitem>
31f6244cc25ab0f8937edc26dbb26ba4f6a01f19Evan Hunt <para>
31f6244cc25ab0f8937edc26dbb26ba4f6a01f19Evan Hunt If the key's publication date is set and is in the past, the
2729aea3c1a720269aaae92ce3a84af1ba0a75ebMark Andrews key is published in the zone.
2729aea3c1a720269aaae92ce3a84af1ba0a75ebMark Andrews </para>
a1271e2404dd42fcc477974bd0a190224f34f5f7Mark Andrews </listitem>
a1271e2404dd42fcc477974bd0a190224f34f5f7Mark Andrews </varlistentry>
a1271e2404dd42fcc477974bd0a190224f34f5f7Mark Andrews
842a3e6d0eb745e34a3cc3e19c8c39b9492ac739Evan Hunt <varlistentry>
842a3e6d0eb745e34a3cc3e19c8c39b9492ac739Evan Hunt <listitem>
842a3e6d0eb745e34a3cc3e19c8c39b9492ac739Evan Hunt <para>
1124950b35ae05a12e804e670607fe5ba775cb4aTinderbox User If the key's activation date is set and in the past, the
dbb012765c735ee0d82dedb116cdc7cf18957814Evan Hunt key is published (regardless of publication date) and
dbb012765c735ee0d82dedb116cdc7cf18957814Evan Hunt used to sign the zone.
dbb012765c735ee0d82dedb116cdc7cf18957814Evan Hunt </para>
d7729155dff87d3c7a2b9103bf6e5164ea4d7dd7Mark Andrews </listitem>
d7729155dff87d3c7a2b9103bf6e5164ea4d7dd7Mark Andrews </varlistentry>
62ec9fd1681ffae7d6b0d54618599ecf650e3100Mark Andrews
62ec9fd1681ffae7d6b0d54618599ecf650e3100Mark Andrews <varlistentry>
850b5e80930907e4747347201dc41e4d04e036f8Mark Andrews <listitem>
850b5e80930907e4747347201dc41e4d04e036f8Mark Andrews <para>
62ec9fd1681ffae7d6b0d54618599ecf650e3100Mark Andrews If the key's revocation date is set and in the past, and the
62ec9fd1681ffae7d6b0d54618599ecf650e3100Mark Andrews key is published, then the key is revoked, and the revoked key
62ec9fd1681ffae7d6b0d54618599ecf650e3100Mark Andrews is used to sign the zone.
41e55d04032c0eefd39d74ffb73657b04fb821ecEvan Hunt </para>
41e55d04032c0eefd39d74ffb73657b04fb821ecEvan Hunt </listitem>
41e55d04032c0eefd39d74ffb73657b04fb821ecEvan Hunt </varlistentry>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt <varlistentry>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt <listitem>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt <para>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt If either of the key's unpublication or deletion dates are set
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt and in the past, the key is NOT published or used to sign the
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt zone, regardless of any other metadata.
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt </para>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt </listitem>
166341d55424ca522eb456a1c7d0211e391f1ac8Evan Hunt </varlistentry>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt </variablelist>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt </listitem>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt </varlistentry>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt
c41d8a22ab5f4a487f4c16b78f23792f78a3a851Francis Dupont <varlistentry>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt <term>-T <replaceable class="parameter">ttl</replaceable></term>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt <listitem>
a165a17a81ff3285f4f4d79785fafb465e626183Evan Hunt <para>
08c67b5b7a54047fbfed423a59b48c86177b9859Evan Hunt Specifies a TTL to be used for new DNSKEY records imported
08c67b5b7a54047fbfed423a59b48c86177b9859Evan Hunt into the zone from the key repository. If not
08c67b5b7a54047fbfed423a59b48c86177b9859Evan Hunt specified, the default is the TTL value from the zone's SOA
e5f9fa7e18d50569a7d723acbb6f641e13ed3787Evan Hunt record. This option is ignored when signing without
e5f9fa7e18d50569a7d723acbb6f641e13ed3787Evan Hunt <option>-S</option>, since DNSKEY records are not imported
e5f9fa7e18d50569a7d723acbb6f641e13ed3787Evan Hunt from the key repository in that case. It is also ignored if
62cce60a15990bf8ec05b4234a5c965a5a8e86c0Evan Hunt there are any pre-existing DNSKEY records at the zone apex,
62cce60a15990bf8ec05b4234a5c965a5a8e86c0Evan Hunt in which case new records' TTL values will be set to match
62cce60a15990bf8ec05b4234a5c965a5a8e86c0Evan Hunt them, or if any of the imported DNSKEY records had a default
62cce60a15990bf8ec05b4234a5c965a5a8e86c0Evan Hunt TTL value. In the event of a a conflict between TTL values in
e2d635d630f6f61fefd3d4475c45b097b16b8a2aEvan Hunt imported keys, the shortest one is used.
e2d635d630f6f61fefd3d4475c45b097b16b8a2aEvan Hunt </para>
e2d635d630f6f61fefd3d4475c45b097b16b8a2aEvan Hunt </listitem>
e2d635d630f6f61fefd3d4475c45b097b16b8a2aEvan Hunt </varlistentry>
0a35160f4eb349188a988d2857e0b3052ad4b778Evan Hunt
0a35160f4eb349188a988d2857e0b3052ad4b778Evan Hunt <varlistentry>
a8cdf2a2e7e9a716a94db550138f1a65000fc19fEvan Hunt <term>-t</term>
a8cdf2a2e7e9a716a94db550138f1a65000fc19fEvan Hunt <listitem>
a8cdf2a2e7e9a716a94db550138f1a65000fc19fEvan Hunt <para>
a8cdf2a2e7e9a716a94db550138f1a65000fc19fEvan Hunt Print statistics at completion.
3249da26fc28297265d444a1f3647f1e6700a2a0Evan Hunt </para>
3249da26fc28297265d444a1f3647f1e6700a2a0Evan Hunt </listitem>
3249da26fc28297265d444a1f3647f1e6700a2a0Evan Hunt </varlistentry>
0666e6db543cda2de2b8472ba49ed9b53c836326Tinderbox User
d0803df3310ad09447c34b972e7594d576f5cbb5Evan Hunt <varlistentry>
d0803df3310ad09447c34b972e7594d576f5cbb5Evan Hunt <term>-u</term>
9d58bbdf12e77d2b62e669bc2965b0788b97731aJeremy C. Reed <listitem>
47c847e286ac1d9dcc1b6dec5430ad9d2abad7b2Evan Hunt <para>
47c847e286ac1d9dcc1b6dec5430ad9d2abad7b2Evan Hunt Update NSEC/NSEC3 chain when re-signing a previously signed
63add83a2699aac4e01be6d1f2d093cfed4f744aMark Andrews zone. With this option, a zone signed with NSEC can be
63add83a2699aac4e01be6d1f2d093cfed4f744aMark Andrews switched to NSEC3, or a zone signed with NSEC3 can
75d747e1c5a30d6ef6c6238c6e27baa11d6f3bf6Mark Andrews be switch to NSEC or to NSEC3 with different parameters.
75d747e1c5a30d6ef6c6238c6e27baa11d6f3bf6Mark Andrews Without this option, <command>dnssec-signzone</command> will
fbc0e37e0c3732b20b0629056e98d712a118637fMark Andrews retain the existing chain when re-signing.
fbc0e37e0c3732b20b0629056e98d712a118637fMark Andrews </para>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews </listitem>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews </varlistentry>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews <varlistentry>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews <term>-v <replaceable class="parameter">level</replaceable></term>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews <listitem>
b8cf73a3b3e21d61f5a06670551ac22e61bcc4b1Mark Andrews <para>
83f69fcd6ef72c9e2ebcb025b66a2ee74176becdEvan Hunt Sets the debugging level.
83f69fcd6ef72c9e2ebcb025b66a2ee74176becdEvan Hunt </para>
83f69fcd6ef72c9e2ebcb025b66a2ee74176becdEvan Hunt </listitem>
83f69fcd6ef72c9e2ebcb025b66a2ee74176becdEvan Hunt </varlistentry>
83f69fcd6ef72c9e2ebcb025b66a2ee74176becdEvan Hunt
d58e33bfabfee19a035031dac633d36659738d56Evan Hunt <varlistentry>
d58e33bfabfee19a035031dac633d36659738d56Evan Hunt <term>-x</term>
d58e33bfabfee19a035031dac633d36659738d56Evan Hunt <listitem>
d58e33bfabfee19a035031dac633d36659738d56Evan Hunt <para>
e45d0508c3460db87afb1f743bc5210522721bb3Evan Hunt Only sign the DNSKEY RRset with key-signing keys, and omit
e45d0508c3460db87afb1f743bc5210522721bb3Evan Hunt signatures from zone-signing keys. (This is similar to the
e45d0508c3460db87afb1f743bc5210522721bb3Evan Hunt <command>dnssec-dnskey-kskonly yes;</command> zone option in
e45d0508c3460db87afb1f743bc5210522721bb3Evan Hunt <command>named</command>.)
f8c990f6c2d3f75120bd67a55e87f21e88e9e5a6Evan Hunt </para>
f8c990f6c2d3f75120bd67a55e87f21e88e9e5a6Evan Hunt </listitem>
f8c990f6c2d3f75120bd67a55e87f21e88e9e5a6Evan Hunt </varlistentry>
f8c990f6c2d3f75120bd67a55e87f21e88e9e5a6Evan Hunt
db8938c993d3eaeae1d86feb1b5da511831a9014Mark Andrews <varlistentry>
db8938c993d3eaeae1d86feb1b5da511831a9014Mark Andrews <term>-z</term>
db8938c993d3eaeae1d86feb1b5da511831a9014Mark Andrews <listitem>
db8938c993d3eaeae1d86feb1b5da511831a9014Mark Andrews <para>
a147de10fe5e19e593d42152ffd6879eca69860dEvan Hunt Ignore KSK flag on key when determining what to sign. This
a147de10fe5e19e593d42152ffd6879eca69860dEvan Hunt causes KSK-flagged keys to sign all records, not just the
a147de10fe5e19e593d42152ffd6879eca69860dEvan Hunt DNSKEY RRset. (This is similar to the
a147de10fe5e19e593d42152ffd6879eca69860dEvan Hunt <command>update-check-ksk no;</command> zone option in
702958d20247bb9e34019cf02d8ec18d4f3b1005Mark Andrews <command>named</command>.)
702958d20247bb9e34019cf02d8ec18d4f3b1005Mark Andrews </para>
702958d20247bb9e34019cf02d8ec18d4f3b1005Mark Andrews </listitem>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </varlistentry>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <varlistentry>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <term>-3 <replaceable class="parameter">salt</replaceable></term>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <listitem>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <para>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews Generate an NSEC3 chain with the given hex encoded salt.
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews A dash (<replaceable class="parameter">salt</replaceable>) can
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews be used to indicate that no salt is to be used when generating the NSEC3 chain.
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </para>
4882e183cac5772ea522811c758c402cd7e8ad5bEvan Hunt </listitem>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </varlistentry>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <varlistentry>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <term>-H <replaceable class="parameter">iterations</replaceable></term>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <listitem>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <para>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews When generating an NSEC3 chain, use this many iterations. The
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews default is 10.
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </para>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </listitem>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews </varlistentry>
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews
cd7f8d18f8ed073ca5478d63f49179286d38d3d6Mark Andrews <varlistentry>
a18fc12ba3d48b66bea298c80f3e3f09f3c91527Evan Hunt <term>-A</term>
a18fc12ba3d48b66bea298c80f3e3f09f3c91527Evan Hunt <listitem>
a18fc12ba3d48b66bea298c80f3e3f09f3c91527Evan Hunt <para>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt When generating an NSEC3 chain set the OPTOUT flag on all
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt NSEC3 records and do not generate NSEC3 records for insecure
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt delegations.
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </para>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt <para>
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt Using this option twice (i.e., <option>-AA</option>)
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt turns the OPTOUT flag off for all records. This is useful
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt when using the <option>-u</option> option to modify an NSEC3
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt chain which previously had OPTOUT set.
ba751492fcc4f161a18b983d4f018a1a52938cb9Evan Hunt </para>
07fb9b83308daea64e50a1f07052addc25c15ec3Mark Andrews </listitem>
07fb9b83308daea64e50a1f07052addc25c15ec3Mark Andrews </varlistentry>
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt <varlistentry>
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt <term>zonefile</term>
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt <listitem>
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt <para>
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt The file containing the zone to be signed.
b751788932cf1a6d98ae83355f38a080125c2f3eEvan Hunt </para>
fb756ba3047770957173ba546257ca43af7ba3e4Mark Andrews </listitem>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt </varlistentry>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt <varlistentry>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt <term>key</term>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt <listitem>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt <para>
7d2b185f16b165e311e5b451324fe9ab9898dcedEvan Hunt Specify which keys should be used to sign the zone. If
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews no keys are specified, then the zone will be examined
39c30670e869062914b6f7245b64b9ebe8747d86Mark Andrews for DNSKEY records at the zone apex. If these are found and
ff6de396a93b9b73a37173059a595f3d295b57cbMark Andrews there are matching private keys, in the current directory,
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt then these will be used for signing.
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt </para>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt </listitem>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt </varlistentry>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt </variablelist>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt </refsect1>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt <refsect1>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt <title>EXAMPLE</title>
789252d55f025db52ee02aa933c9f09a4aadfa97Evan Hunt <para>
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Hunt The following command signs the <userinput>example.com</userinput>
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Hunt zone with the DSA key generated by <command>dnssec-keygen</command>
e851ea826066ac5a5b01c2c23218faa0273a12e8Evan Hunt (Kexample.com.+003+17247). Because the <command>-S</command> option
d0e3216c217bf790c4a582191658c2a1900ff79fMark Andrews is not being used, the zone's keys must be in the master file
d0e3216c217bf790c4a582191658c2a1900ff79fMark Andrews (<filename>db.example.com</filename>). This invocation looks
d0e3216c217bf790c4a582191658c2a1900ff79fMark Andrews for <filename>dsset</filename> files, in the current directory,
e9649ece3bf32ff43faea13c76bbba7813d7e139Mark Andrews so that DS records can be imported from them (<command>-g</command>).
e9649ece3bf32ff43faea13c76bbba7813d7e139Mark Andrews </para>
e9649ece3bf32ff43faea13c76bbba7813d7e139Mark Andrews<programlisting>% dnssec-signzone -g -o example.com db.example.com \
2b258a1f5b02488c6a36ac1b0a7535b42ea6fd34Evan HuntKexample.com.+003+17247
2b258a1f5b02488c6a36ac1b0a7535b42ea6fd34Evan Huntdb.example.com.signed
c14ba7107063650e7f4329e8c54adca57913381bEvan Hunt%</programlisting>
3f4a0e80fabe0233086e127aaabc6e68d6975c3aEvan Hunt <para>
c14ba7107063650e7f4329e8c54adca57913381bEvan Hunt In the above example, <command>dnssec-signzone</command> creates
b93ef543ab29be2c2d15049e02e66a31b27284aeMark Andrews the file <filename>db.example.com.signed</filename>. This
fa467e60c590072fd6848522456eb2cc41582c59Mark Andrews file should be referenced in a zone statement in a
fa467e60c590072fd6848522456eb2cc41582c59Mark Andrews <filename>named.conf</filename> file.
33a296aa3a3d5e808cabf556c95f29cc1eecff16Evan Hunt </para>
33a296aa3a3d5e808cabf556c95f29cc1eecff16Evan Hunt <para>
b93ef543ab29be2c2d15049e02e66a31b27284aeMark Andrews This example re-signs a previously signed zone with default parameters.
161e803a5608956271d8120be37a1b383d14b647Mark Andrews The private keys are assumed to be in the current directory.
161e803a5608956271d8120be37a1b383d14b647Mark Andrews </para>
161e803a5608956271d8120be37a1b383d14b647Mark Andrews<programlisting>% cp db.example.com.signed db.example.com
5f8d6cec48cef9055359c628942d633693f732b2Evan Hunt% dnssec-signzone -o example.com db.example.com
5f8d6cec48cef9055359c628942d633693f732b2Evan Huntdb.example.com.signed
5f8d6cec48cef9055359c628942d633693f732b2Evan Hunt%</programlisting>
0606c47750ad362909f010db2ef1ff8dcc96f9cbEvan Hunt </refsect1>
0606c47750ad362909f010db2ef1ff8dcc96f9cbEvan Hunt
0606c47750ad362909f010db2ef1ff8dcc96f9cbEvan Hunt <refsect1>
0606c47750ad362909f010db2ef1ff8dcc96f9cbEvan Hunt <title>SEE ALSO</title>
9b895f30f1734fd463a02b27cfd0cf36ec9893d5Evan Hunt <para><citerefentry>
9b895f30f1734fd463a02b27cfd0cf36ec9893d5Evan Hunt <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
9b895f30f1734fd463a02b27cfd0cf36ec9893d5Evan Hunt </citerefentry>,
9b895f30f1734fd463a02b27cfd0cf36ec9893d5Evan Hunt <citetitle>BIND 9 Administrator Reference Manual</citetitle>,
e4d0018d4c9c05fb2a2dbac05a67cc9ddbe2c3d9Mark Andrews <citetitle>RFC 4033</citetitle>, <citetitle>RFC 4641</citetitle>.
e4d0018d4c9c05fb2a2dbac05a67cc9ddbe2c3d9Mark Andrews </para>
e4d0018d4c9c05fb2a2dbac05a67cc9ddbe2c3d9Mark Andrews </refsect1>
00112618bc042f734de7b5ac86506cacb9acf36dMark Andrews
00112618bc042f734de7b5ac86506cacb9acf36dMark Andrews <refsect1>
00112618bc042f734de7b5ac86506cacb9acf36dMark Andrews <title>AUTHOR</title>
0bbe3273a224aa07b6af4165a26fd26d6f30c0adEvan Hunt <para><corpauthor>Internet Systems Consortium</corpauthor>
0bbe3273a224aa07b6af4165a26fd26d6f30c0adEvan Hunt </para>
0bbe3273a224aa07b6af4165a26fd26d6f30c0adEvan Hunt </refsect1>
0bbe3273a224aa07b6af4165a26fd26d6f30c0adEvan Hunt
445a354e63f84ac884d923f697b598b83288dc64Evan Hunt</refentry><!--
445a354e63f84ac884d923f697b598b83288dc64Evan Hunt - Local variables:
445a354e63f84ac884d923f697b598b83288dc64Evan Hunt - mode: sgml
7d65cbaca0839ae23358dce26de426be1301657aMark Andrews - End:
7d65cbaca0839ae23358dce26de426be1301657aMark Andrews-->
7d65cbaca0839ae23358dce26de426be1301657aMark Andrews