dnssec-signzone.html revision 089c63b69cdf6803aa8901aae3f2fbae58969511
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
75c0816e8295e180f4bc7f10db3d0d880383bc1cMark Andrews - Copyright (C) 2000-2003 Internet Software Consortium.
4a14ce5ba00ab7bc55c99ffdcf59c7a4ab902721Automatic Updater - Permission to use, copy, modify, and/or distribute this software for any
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington - purpose with or without fee is hereby granted, provided that the above
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington - copyright notice and this permission notice appear in all copies.
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<!-- $Id: dnssec-signzone.html,v 1.45 2009/12/04 01:13:44 tbox Exp $ -->
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
e21a2904f02a03fa06b6db04d348f65fe9c67b2bMark Andrews<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-P</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<a name="id2543596"></a><h2>DESCRIPTION</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span><strong class="command">dnssec-signzone</strong></span>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signs a zone. It generates
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein NSEC and RRSIG records and produces a signed version of the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone. The security status of delegations from the signed zone
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein (that is, whether the child zones are secure or not) is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein determined by the presence or absence of a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="filename">keyset</code> file for each child zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Verify all generated signatures.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specifies the DNS class of the zone.
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Compatibility mode: Generate a
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater file in addition to
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater when signing a zone, for use by older versions of
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <span><strong class="command">dnssec-signzone</strong></span>.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Look for <code class="filename">dsset-</code> or
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <code class="filename">keyset-</code> files in <code class="option">directory</code>.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Uses a crypto hardware (OpenSSL engine) for the crypto operations
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater it supports, for instance signing with private keys from
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater a secure key store. When compiled with PKCS#11 support
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater it defaults to pkcs11; the empty name resets it to no engine.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Generate DS records for child zones from
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein file. Existing DS records will be removed.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Key repository: Specify a directory to search for DNSSEC keys.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If not specified, defaults to the current directory.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Treat specified key as a key signing key ignoring any
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein key flags. This option may be specified multiple times.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Generate a DLV set in addition to the key (DNSKEY) and DS sets.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The domain is appended to the name of the records.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specify the date and time when the generated RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein become valid. This can be either an absolute or relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time. An absolute start time is indicated by a number
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in YYYYMMDDHHMMSS notation; 20000530144500 denotes
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein 14:45:00 UTC on May 30th, 2000. A relative start time is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein indicated by +N, which is N seconds from the current time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If no <code class="option">start-time</code> is specified, the current
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time minus 1 hour (to allow for clock skew) is used.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Specify the date and time when the generated RRSIG records
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater expire. As with <code class="option">start-time</code>, an absolute
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time is indicated in YYYYMMDDHHMMSS notation. A time relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein to the start time is indicated with +N, which is N seconds from
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the start time. A time relative to the current time is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein indicated with now+N. If no <code class="option">end-time</code> is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein specified, 30 days from the start time is used as a default.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="option">end-time</code> must be later than
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The name of the output file containing the signed zone. The
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein default is to append <code class="filename">.signed</code> to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein input filename.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Prints a short summary of the options and arguments to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <span><strong class="command">dnssec-signzone</strong></span>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein When a previously-signed zone is passed as input, records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein may be resigned. The <code class="option">interval</code> option
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein specifies the cycle interval as an offset from the current
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time (in seconds). If a RRSIG record expires after the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein cycle interval, it is retained. Otherwise, it is considered
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein to be expiring soon, and it will be replaced.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The default cycle interval is one quarter of the difference
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein between the signature end and start times. So if neither
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="option">end-time</code> or <code class="option">start-time</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein are specified, <span><strong class="command">dnssec-signzone</strong></span>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews signatures that are valid for 30 days, with a cycle
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews interval of 7.5 days. Therefore, if any existing RRSIG records
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews are due to expire in less than 7.5 days, they would be
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews The format of the input zone file.
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews Possible formats are <span><strong class="command">"text"</strong></span> (default)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein and <span><strong class="command">"raw"</strong></span>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein This option is primarily intended to be used for dynamic
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signed zones so that the dumped zone file in a non-text
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein format containing updates can be signed directly.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The use of this option does not make much sense for
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein non-dynamic zones.
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein When signing a zone with a fixed signature lifetime, all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein RRSIG records issued at the time of signing expires
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein simultaneously. If the zone is incrementally signed, i.e.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein a previously-signed zone is passed as input to the signer,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein all expired signatures have to be regenerated at about the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein same time. The <code class="option">jitter</code> option specifies a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein jitter window that will be used to randomize the signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein expire time, thus spreading incremental signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein regeneration over time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Signature lifetime jitter also to some extent benefits
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein validators and servers by spreading out cache expiration,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein i.e. if large numbers of RRSIGs don't expire at the same time
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein from all caches there will be less congestion than if all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein validators need to refetch at mostly the same time.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews Specifies the number of threads to use. By default, one
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews thread is started for each detected CPU.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews The SOA serial number format of the signed zone.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews Possible formats are <span><strong class="command">"keep"</strong></span> (default),
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews <span><strong class="command">"increment"</strong></span> and
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews <span><strong class="command">"unixtime"</strong></span>.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dd><p>Do not modify the SOA serial number.</p></dd>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>Increment the SOA serial number using RFC 1982
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>Set the SOA serial number to the number of seconds
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews The zone origin. If not specified, the name of the zone file
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews is assumed to be the origin.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The format of the output file containing the signed zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Possible formats are <span><strong class="command">"text"</strong></span> (default)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein and <span><strong class="command">"raw"</strong></span>.
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater Use pseudo-random data when signing the zone. This is faster,
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater but less secure, than using real random data. This option
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater may be useful when signing large zones or when the entropy
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater source is limited.
1c51f79aba598e5e20bde66aea0237e347f6d5ceAutomatic Updater Disable post sign verification tests.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The post sign verification test ensures that for each algorithm
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in use there is at least one non revoked self signed KSK key,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein that all revoked KSK keys are self signed, and that all records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in the zone are signed by the algorithm.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein This option skips these tests.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specifies the source of randomness. If the operating
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein system does not provide a <code class="filename">/dev/random</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein or equivalent device, the default source of randomness
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater is keyboard input. <code class="filename">randomdev</code>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater the name of a character device or file containing random
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater data to be used instead of the default. The special value
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <code class="filename">keyboard</code> indicates that keyboard
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater input should be used.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Smart signing: Instructs <span><strong class="command">dnssec-signzone</strong></span> to
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater search the key repository for keys that match the zone being
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater signed, and to include them in the zone if appropriate.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater When a key is found, its timing metadata is examined to
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater determine how it should be used, according to the following
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater rules. Each successive rule takes priority over the prior
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If no timing metadata has been set for the key, the key is
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater published in the zone and used to sign the zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If the key's publication date is set and is in the past, the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater key is published in the zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If the key's activation date is set and in the past, the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater key is published (regardless of publication date) and
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater used to sign the zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If the key's revocation date is set and in the past, and the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater key is published, then the key is revoked, and the revoked key
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater is used to sign the zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If either of the key's unpublication or deletion dates are set
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater and in the past, the key is NOT published or used to sign the
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater zone, regardless of any other metadata.
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Specifies the TTL to be used for new DNSKEY records imported
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater into the zone from the key repository. If not specified,
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater the default is the minimum TTL value from the zone's SOA
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein record. This option is ignored when signing without
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="option">-S</code>, since DNSKEY records are not imported
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein from the key repository in that case. It is also ignored if
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein there are any pre-existing DNSKEY records at the zone apex,
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater in which case new records' TTL values will be set to match
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater Print statistics at completion.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Update NSEC/NSEC3 chain when re-signing a previously signed
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone. With this option, a zone signed with NSEC can be
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein switched to NSEC3, or a zone signed with NSEC3 can
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein be switch to NSEC or to NSEC3 with different parameters.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Without this option, <span><strong class="command">dnssec-signzone</strong></span> will
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein retain the existing chain when re-signing.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater Sets the debugging level.
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater Only sign the DNSKEY RRset with key-signing keys, and omit
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater signatures from zone-signing keys. (This is similar to the
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater <span><strong class="command">dnssec-dnskey-kskonly yes;</strong></span> zone option in
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater <span><strong class="command">named</strong></span>.)
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater Ignore KSK flag on key when determining what to sign. This
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater causes KSK-flagged keys to sign all records, not just the
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater DNSKEY RRset. (This is similar to the
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater <span><strong class="command">update-check-ksk no;</strong></span> zone option in
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater <span><strong class="command">named</strong></span>.)
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<dt><span class="term">-3 <em class="replaceable"><code>salt</code></em></span></dt>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater Generate an NSEC3 chain with the given hex encoded salt.
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater A dash (<em class="replaceable"><code>salt</code></em>) can
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater be used to indicate that no salt is to be used when generating the NSEC3 chain.
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<dt><span class="term">-H <em class="replaceable"><code>iterations</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein When generating an NSEC3 chain, use this many interations. The
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein default is 10.
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews When generating an NSEC3 chain set the OPTOUT flag on all
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews NSEC3 records and do not generate NSEC3 records for insecure
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews delegations.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Using this option twice (i.e., <code class="option">-AA</code>)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein turns the OPTOUT flag off for all records. This is useful
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein when using the <code class="option">-u</code> option to modify an NSEC3
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater chain which previously had OPTOUT set.
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews The file containing the zone to be signed.
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews Specify which keys should be used to sign the zone. If
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews no keys are specified, then the zone will be examined
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews for DNSKEY records at the zone apex. If these are found and
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews there are matching private keys, in the current directory,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein then these will be used for signing.
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews The following command signs the <strong class="userinput"><code>example.com</code></strong>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews (Kexample.com.+003+17247). Because the <span><strong class="command">-S</strong></span> option
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews is not being used, the zone's keys must be in the master file
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews (<code class="filename">db.example.com</code>). This invocation looks
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews for <code class="filename">dsset</code> files, in the current directory,
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews so that DS records can be imported from them (<span><strong class="command">-g</strong></span>).
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the file <code class="filename">db.example.com.signed</code>. This
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein file should be referenced in a zone statement in a
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater <code class="filename">named.conf</code> file.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein This example re-signs a previously signed zone with default parameters.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The private keys are assumed to be in the current directory.