dnssec-signzone.docbook revision 0c27b3fe77ac1d5094ba3521e8142d9e7973133f
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley - Copyright (C) 2000-2009, 2011-2016 Internet Systems Consortium, Inc. ("ISC")
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley - This Source Code Form is subject to the terms of the Mozilla Public
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley - License, v. 2.0. If a copy of the MPL was not distributed with this
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley - file, You can obtain one at http://mozilla.org/MPL/2.0/.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley<!-- Converted by db4-upgrade version 1.0 -->
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley<refentry xmlns="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-signzone">
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refentryinfo>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </refentryinfo>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refentrytitle><application>dnssec-signzone</application></refentrytitle>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refnamediv>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refname><application>dnssec-signzone</application></refname>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refpurpose>DNSSEC zone signing tool</refpurpose>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </refnamediv>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </copyright>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </copyright>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refsynopsisdiv>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-a</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-D</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-g</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-h</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">key</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">serial</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-M <replaceable class="parameter">domain</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-P</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-p</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-Q</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-R</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-S</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-t</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-u</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-V</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-X <replaceable class="parameter">extended end-time</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-x</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-z</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-3 <replaceable class="parameter">salt</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-H <replaceable class="parameter">iterations</replaceable></option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <arg choice="opt" rep="norepeat"><option>-A</option></arg>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </cmdsynopsis>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </refsynopsisdiv>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <refsection><info><title>DESCRIPTION</title></info>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley signs a zone. It generates
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley NSEC and RRSIG records and produces a signed version of the
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley zone. The security status of delegations from the signed zone
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley (that is, whether the child zones are secure or not) is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley determined by the presence or absence of a
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <filename>keyset</filename> file for each child zone.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </refsection>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <variablelist>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Verify all generated signatures.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-c <replaceable class="parameter">class</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Specifies the DNS class of the zone.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Compatibility mode: Generate a
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <filename>keyset-<replaceable>zonename</replaceable></filename>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley file in addition to
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <filename>dsset-<replaceable>zonename</replaceable></filename>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley when signing a zone, for use by older versions of
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-d <replaceable class="parameter">directory</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <filename>keyset-</filename> files in <option>directory</option>.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Output only those record types automatically managed by
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <command>dnssec-signzone</command>, i.e. RRSIG, NSEC,
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley NSEC3 and NSEC3PARAM records. If smart signing
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley (<option>-S</option>) is used, DNSKEY records are also
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley included. The resulting file can be included in the original
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley zone file with <command>$INCLUDE</command>. This option
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <option>-O map</option>, or serial number updating.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-E <replaceable class="parameter">engine</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley When applicable, specifies the hardware to use for
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley cryptographic operations, such as a secure key store used
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley for signing.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley When BIND is built with OpenSSL PKCS#11 support, this defaults
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley to the string "pkcs11", which identifies an OpenSSL engine
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley that can drive a cryptographic accelerator or hardware service
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley module. When BIND is built with native PKCS#11 cryptography
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley (--enable-native-pkcs11), it defaults to the path of the PKCS#11
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley provider library specified via "--with-pkcs11".
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Generate DS records for child zones from
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <filename>dsset-</filename> or <filename>keyset-</filename>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley file. Existing DS records will be removed.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-K <replaceable class="parameter">directory</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Key repository: Specify a directory to search for DNSSEC keys.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley If not specified, defaults to the current directory.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-k <replaceable class="parameter">key</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Treat specified key as a key signing key ignoring any
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley key flags. This option may be specified multiple times.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-l <replaceable class="parameter">domain</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Generate a DLV set in addition to the key (DNSKEY) and DS sets.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley The domain is appended to the name of the records.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-M <replaceable class="parameter">maxttl</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Sets the maximum TTL for the signed zone.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Any TTL higher than <replaceable>maxttl</replaceable> in the
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley input zone will be reduced to <replaceable>maxttl</replaceable>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley in the output. This provides certainty as to the largest
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley possible TTL in the signed zone, which is useful to know when
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley rolling keys because it is the longest possible time before
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley signatures that have been retrieved by resolvers will expire
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley from resolver caches. Zones that are signed with this
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley option should be configured to use a matching
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <option>max-zone-ttl</option> in <filename>named.conf</filename>.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley (Note: This option is incompatible with <option>-D</option>,
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley because it modifies non-DNSSEC data in the output zone.)
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-s <replaceable class="parameter">start-time</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Specify the date and time when the generated RRSIG records
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley become valid. This can be either an absolute or relative
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley time. An absolute start time is indicated by a number
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley in YYYYMMDDHHMMSS notation; 20000530144500 denotes
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley 14:45:00 UTC on May 30th, 2000. A relative start time is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley indicated by +N, which is N seconds from the current time.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley If no <option>start-time</option> is specified, the current
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley time minus 1 hour (to allow for clock skew) is used.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-e <replaceable class="parameter">end-time</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Specify the date and time when the generated RRSIG records
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley expire. As with <option>start-time</option>, an absolute
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley time is indicated in YYYYMMDDHHMMSS notation. A time relative
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley to the start time is indicated with +N, which is N seconds from
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley the start time. A time relative to the current time is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley indicated with now+N. If no <option>end-time</option> is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley specified, 30 days from the start time is used as a default.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-X <replaceable class="parameter">extended end-time</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Specify the date and time when the generated RRSIG records
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley for the DNSKEY RRset will expire. This is to be used in cases
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley when the DNSKEY signatures need to persist longer than
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley signatures on other records; e.g., when the private component
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley of the KSK is kept offline and the KSK signature is to be
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley refreshed manually.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley time is indicated in YYYYMMDDHHMMSS notation. A time relative
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley to the start time is indicated with +N, which is N seconds from
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley the start time. A time relative to the current time is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley indicated with now+N. If no <option>extended end-time</option> is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley specified, the value of <option>end-time</option> is used as
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley the default. (<option>end-time</option>, in turn, defaults to
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley 30 days from the start time.) <option>extended end-time</option>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-f <replaceable class="parameter">output-file</replaceable></term>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley The name of the output file containing the signed zone. The
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley default is to append <filename>.signed</filename> to
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley the input filename. If <option>output-file</option> is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley set to <literal>"-"</literal>, then the signed zone is
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley written to the standard output, with a default output
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley format of "full".
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Prints a short summary of the options and arguments to
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley Prints version information.
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley </varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <varlistentry>
6ea1b817e31b89a627e146fe69e23ea0a64c89ecBob Halley <term>-i <replaceable class="parameter">interval</replaceable></term>
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
Kexample.com.+003+17247