dnssec-signzone.docbook revision 5a0fe4f4834430539ba734f257064742916e3aa4
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco - Copyright (C) 2000-2009, 2011-2017 Internet Systems Consortium, Inc. ("ISC")
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco - This Source Code Form is subject to the terms of the Mozilla Public
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco - License, v. 2.0. If a copy of the MPL was not distributed with this
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco - file, You can obtain one at http://mozilla.org/MPL/2.0/.
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco<!-- Converted by db4-upgrade version 1.0 -->
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco<refentry xmlns:db="http://docbook.org/ns/docbook" version="5.0" xml:id="man.dnssec-signzone">
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco <refentryinfo>
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco <corpauthor>Internet Systems Consortium, Inc.</corpauthor>
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco </refentryinfo>
54ba62a2c6e74332ffc742cb23faf21615b5d39fLubos Kosco <refentrytitle><application>dnssec-signzone</application></refentrytitle>
b4a94e1e9bfb77dcba635f9e3cfd4fd4276b64ccLubos Kosco <refnamediv>
b4a94e1e9bfb77dcba635f9e3cfd4fd4276b64ccLubos Kosco <refname><application>dnssec-signzone</application></refname>
3155e2f2ec2ffa6e5e98f61f2deb990078ac9881Chris Eldredge <refpurpose>DNSSEC zone signing tool</refpurpose>
3155e2f2ec2ffa6e5e98f61f2deb990078ac9881Chris Eldredge </refnamediv>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <refsynopsisdiv>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-a</option></arg>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-c <replaceable class="parameter">class</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-D</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-E <replaceable class="parameter">engine</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-g</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-h</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-K <replaceable class="parameter">directory</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-k <replaceable class="parameter">key</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-L <replaceable class="parameter">serial</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-M <replaceable class="parameter">maxttl</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-N <replaceable class="parameter">soa-serial-format</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-P</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-p</option></arg>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-Q</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-R</option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-S</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-T <replaceable class="parameter">ttl</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-t</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-u</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-v <replaceable class="parameter">level</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-V</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-X <replaceable class="parameter">extended end-time</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-x</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-z</option></arg>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-3 <replaceable class="parameter">salt</replaceable></option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="opt" rep="norepeat"><option>-H <replaceable class="parameter">iterations</replaceable></option></arg>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <arg choice="opt" rep="norepeat"><option>-A</option></arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <arg choice="req" rep="norepeat">zonefile</arg>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen </cmdsynopsis>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen </refsynopsisdiv>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <refsection><info><title>DESCRIPTION</title></info>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen signs a zone. It generates
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen NSEC and RRSIG records and produces a signed version of the
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen zone. The security status of delegations from the signed zone
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen (that is, whether the child zones are secure or not) is
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen determined by the presence or absence of a
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <filename>keyset</filename> file for each child zone.
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <refsection><info><title>OPTIONS</title></info>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <variablelist>
1a2218353383d8cc9d1c01c95ad0a5fe94685f12Vladimir Kotal <varlistentry>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen Verify all generated signatures.
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen </varlistentry>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <varlistentry>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <term>-c <replaceable class="parameter">class</replaceable></term>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen Specifies the DNS class of the zone.
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen </varlistentry>
a39bcfe2e58183496eab6572675e2896e5045fa7Knut Anders Hatlen <varlistentry>
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen Compatibility mode: Generate a
3733e9d930124c0050f9d5f27ee7a2f1b1b0bb2eKnut Anders Hatlen <filename>keyset-<replaceable>zonename</replaceable></filename>
3155e2f2ec2ffa6e5e98f61f2deb990078ac9881Chris Eldredge file in addition to
signatures on other records; e.g., when the private component
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
Kexample.com.+003+17247