dnssec-signzone.docbook revision b5ad6dfea4cc3e7d1d322ac99f1e5a31096837c4
1633838b8255282d10af15c5c84cee5a51466712Bob Halley<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.0//EN"
94d102893aeb8ecea49dcda64e742835ffe0c102Bob Halley "http://www.oasis-open.org/docbook/xml/4.0/docbookx.dtd"
1633838b8255282d10af15c5c84cee5a51466712Bob Halley [<!ENTITY mdash "—">]>
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - Copyright (C) 2000-2003 Internet Software Consortium.
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - Permission to use, copy, modify, and distribute this software for any
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - purpose with or without fee is hereby granted, provided that the above
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - copyright notice and this permission notice appear in all copies.
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
1633838b8255282d10af15c5c84cee5a51466712Bob Halley - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
d25afd60ee2286cb171c4960a790f3d7041b6f85Bob Halley - PERFORMANCE OF THIS SOFTWARE.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley<!-- $Id: dnssec-signzone.docbook,v 1.20 2005/07/19 04:55:20 marka Exp $ -->
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <refentryinfo>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </refentryinfo>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <refentrytitle><application>dnssec-signzone</application></refentrytitle>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <refnamediv>
3740b569ae76295b941d57a724a43beb75b533baBob Halley <refname><application>dnssec-signzone</application></refname>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <refpurpose>DNSSEC zone signing tool</refpurpose>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </refnamediv>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </copyright>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </copyright>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <refsynopsisdiv>
3740b569ae76295b941d57a724a43beb75b533baBob Halley <cmdsynopsis>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-d <replaceable class="parameter">directory</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-e <replaceable class="parameter">end-time</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-f <replaceable class="parameter">output-file</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-k <replaceable class="parameter">key</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-i <replaceable class="parameter">interval</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-I <replaceable class="parameter">input-format</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-j <replaceable class="parameter">jitter</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-n <replaceable class="parameter">nthreads</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-o <replaceable class="parameter">origin</replaceable></option></arg>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <arg><option>-O <replaceable class="parameter">output-format</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-r <replaceable class="parameter">randomdev</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-s <replaceable class="parameter">start-time</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </cmdsynopsis>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </refsynopsisdiv>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley signs a zone. It generates
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley NSEC and RRSIG records and produces a signed version of the
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley zone. The security status of delegations from the signed zone
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley (that is, whether the child zones are secure or not) is
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley determined by the presence or absence of a
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <filename>keyset</filename> file for each child zone.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <variablelist>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley Verify all generated signatures.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <term>-c <replaceable class="parameter">class</replaceable></term>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley Specifies the DNS class of the zone.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <term>-k <replaceable class="parameter">key</replaceable></term>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley Treat specified key as a key signing key ignoring any
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley key flags. This option may be specified multiple times.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley <term>-l <replaceable class="parameter">domain</replaceable></term>
4bc30f45a225947a298f706a8522c9d30915d137Bob Halley Generate a DLV set in addition to the key (DNSKEY) and DS sets.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley The domain is appended to the name of the records.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <term>-d <replaceable class="parameter">directory</replaceable></term>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley Generate DS records for child zones from keyset files.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley Existing DS records will be removed.
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley </varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <varlistentry>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley <term>-s <replaceable class="parameter">start-time</replaceable></term>
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley Specify the date and time when the generated RRSIG records
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley become valid. This can be either an absolute or relative
c50fd34a4e0e6978f8ca5f6f3ad8545549c3cfeeBob Halley time. An absolute start time is indicated by a number
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time