dnssec-signzone.html revision 3b2c6af63e0367c6eabe0a21ca23841ca87cd22f
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington<!--
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
75c0816e8295e180f4bc7f10db3d0d880383bc1cMark Andrews - Copyright (C) 2000-2003 Internet Software Consortium.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein -
4a14ce5ba00ab7bc55c99ffdcf59c7a4ab902721Automatic Updater - Permission to use, copy, modify, and/or distribute this software for any
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington - purpose with or without fee is hereby granted, provided that the above
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington - copyright notice and this permission notice appear in all copies.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein -
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8a66318e41ed14c5a88130e8c362610e8faa2121Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
0b062f4990db5cc6db2fe3398926f71b92a67407Brian Wellington-->
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater<!-- $Id: dnssec-signzone.html,v 1.43 2009/10/12 23:15:22 tbox Exp $ -->
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<html>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<head>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<title>dnssec-signzone</title>
e21a2904f02a03fa06b6db04d348f65fe9c67b2bMark Andrews<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</head>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
5a4557e8de2951a2796676b5ec4b6a90caa5be14Mark Andrews<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="refnamediv">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<h2>Name</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span class="application">dnssec-signzone</span> &#8212; DNSSEC zone signing tool</p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="refsynopsisdiv">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<h2>Synopsis</h2>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-P</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="refsect1" lang="en">
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<a name="id2543596"></a><h2>DESCRIPTION</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span><strong class="command">dnssec-signzone</strong></span>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signs a zone. It generates
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein NSEC and RRSIG records and produces a signed version of the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone. The security status of delegations from the signed zone
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein (that is, whether the child zones are secure or not) is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein determined by the presence or absence of a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="filename">keyset</code> file for each child zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="refsect1" lang="en">
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<a name="id2543611"></a><h2>OPTIONS</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="variablelist"><dl>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-a</span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Verify all generated signatures.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specifies the DNS class of the zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater<dt><span class="term">-C</span></dt>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater<dd><p>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Compatibility mode: Generate a
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater file in addition to
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater when signing a zone, for use by older versions of
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <span><strong class="command">dnssec-signzone</strong></span>.
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Look for <code class="filename">dsset-</code> or
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <code class="filename">keyset-</code> files in <code class="option">directory</code>.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<dd><p>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater Uses a crypto hardware (OpenSSL engine) for the crypto operations
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater it supports, for instance signing with private keys from
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater a secure key store. When compiled with PKCS#11 support
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater it defaults to pcks11, the empty name resets it to no engine.
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater </p></dd>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<dt><span class="term">-g</span></dt>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater<dd><p>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater Generate DS records for child zones from
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater file. Existing DS records will be removed.
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater </p></dd>
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater<dd><p>
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater Key repository: Specify a directory to search for DNSSEC keys.
64affc54f96a2c71cbd10ed71e246ce0746259aaAutomatic Updater If not specified, defaults to the current directory.
8ec3c085233cedb22b05da36e2773c8f357a7e45Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Treat specified key as a key signing key ignoring any
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater key flags. This option may be specified multiple times.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Generate a DLV set in addition to the key (DNSKEY) and DS sets.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater The domain is appended to the name of the records.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specify the date and time when the generated RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein become valid. This can be either an absolute or relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time. An absolute start time is indicated by a number
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in YYYYMMDDHHMMSS notation; 20000530144500 denotes
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein 14:45:00 UTC on May 30th, 2000. A relative start time is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein indicated by +N, which is N seconds from the current time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If no <code class="option">start-time</code> is specified, the current
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time minus 1 hour (to allow for clock skew) is used.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specify the date and time when the generated RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein expire. As with <code class="option">start-time</code>, an absolute
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time is indicated in YYYYMMDDHHMMSS notation. A time relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein to the start time is indicated with +N, which is N seconds from
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the start time. A time relative to the current time is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein indicated with now+N. If no <code class="option">end-time</code> is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein specified, 30 days from the start time is used as a default.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="option">end-time</code> must be later than
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <code class="option">start-time</code>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The name of the output file containing the signed zone. The
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein default is to append <code class="filename">.signed</code> to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein input filename.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-h</span></dt>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater<dd><p>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Prints a short summary of the options and arguments to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <span><strong class="command">dnssec-signzone</strong></span>.
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater </p></dd>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater<dd>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater<p>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater When a previously-signed zone is passed as input, records
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater may be resigned. The <code class="option">interval</code> option
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater specifies the cycle interval as an offset from the current
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater time (in seconds). If a RRSIG record expires after the
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater cycle interval, it is retained. Otherwise, it is considered
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater to be expiring soon, and it will be replaced.
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater </p>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater<p>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater The default cycle interval is one quarter of the difference
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater between the signature end and start times. So if neither
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater <code class="option">end-time</code> or <code class="option">start-time</code>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater are specified, <span><strong class="command">dnssec-signzone</strong></span>
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater generates
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater signatures that are valid for 30 days, with a cycle
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater interval of 7.5 days. Therefore, if any existing RRSIG records
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater are due to expire in less than 7.5 days, they would be
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater replaced.
60a900e83bab52c3f023be66654f3ab023172778Automatic Updater </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The format of the input zone file.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Possible formats are <span><strong class="command">"text"</strong></span> (default)
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews and <span><strong class="command">"raw"</strong></span>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein This option is primarily intended to be used for dynamic
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signed zones so that the dumped zone file in a non-text
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein format containing updates can be signed directly.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The use of this option does not make much sense for
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein non-dynamic zones.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews When signing a zone with a fixed signature lifetime, all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein RRSIG records issued at the time of signing expires
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein simultaneously. If the zone is incrementally signed, i.e.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein a previously-signed zone is passed as input to the signer,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein all expired signatures have to be regenerated at about the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein same time. The <code class="option">jitter</code> option specifies a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein jitter window that will be used to randomize the signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein expire time, thus spreading incremental signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein regeneration over time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Signature lifetime jitter also to some extent benefits
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein validators and servers by spreading out cache expiration,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein i.e. if large numbers of RRSIGs don't expire at the same time
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein from all caches there will be less congestion than if all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein validators need to refetch at mostly the same time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dd><p>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews Specifies the number of threads to use. By default, one
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews thread is started for each detected CPU.
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews </p></dd>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dd>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<p>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews The SOA serial number format of the signed zone.
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews Possible formats are <span><strong class="command">"keep"</strong></span> (default),
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews <span><strong class="command">"increment"</strong></span> and
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews <span><strong class="command">"unixtime"</strong></span>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="variablelist"><dl>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>Do not modify the SOA serial number.</p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>Increment the SOA serial number using RFC 1982
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews arithmetics.</p></dd>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>Set the SOA serial number to the number of seconds
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein since epoch.</p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</dl></div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein</dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The zone origin. If not specified, the name of the zone file
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein is assumed to be the origin.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The format of the output file containing the signed zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Possible formats are <span><strong class="command">"text"</strong></span> (default)
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein and <span><strong class="command">"raw"</strong></span>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-p</span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Use pseudo-random data when signing the zone. This is faster,
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews but less secure, than using real random data. This option
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews may be useful when signing large zones or when the entropy
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews source is limited.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews </p></dd>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term">-P</span></dt>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dd>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<p>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews Disable post sign verification tests.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews </p>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<p>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews The post sign verification test ensures that for each algorithm
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews in use there is at least one non revoked self signed KSK key,
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews that all revoked KSK keys are self signed, and that all records
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews in the zone are signed by the algorithm.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews This option skips these tests.
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews </p>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews</dd>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
52ece689e0265f9a3e518de5b2539e749f6d35acMark Andrews<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Specifies the source of randomness. If the operating
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein system does not provide a <code class="filename">/dev/random</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein or equivalent device, the default source of randomness
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein is keyboard input. <code class="filename">randomdev</code>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein specifies
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews the name of a character device or file containing random
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews data to be used instead of the default. The special value
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews <code class="filename">keyboard</code> indicates that keyboard
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews input should be used.
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews </p></dd>
94fc951a9b5679def2a05387a5c251f5cb8eb9c9Mark Andrews<dt><span class="term">-S</span></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Smart signing: Instructs <span><strong class="command">dnssec-signzone</strong></span> to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein search the key repository for keys that match the zone being
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signed, and to include them in the zone if appropriate.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater When a key is found, its timing metadata is examined to
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater determine how it should be used, according to the following
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater rules. Each successive rule takes priority over the prior
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater ones:
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater </p>
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater<div class="variablelist"><dl>
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater<dt></dt>
1c51f79aba598e5e20bde66aea0237e347f6d5ceAutomatic Updater<dd><p>
1c51f79aba598e5e20bde66aea0237e347f6d5ceAutomatic Updater If no timing metadata has been set for the key, the key is
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater published in the zone and used to sign the zone.
1c51f79aba598e5e20bde66aea0237e347f6d5ceAutomatic Updater </p></dd>
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater<dt></dt>
6283056805887de88040698685b8e1936a1f7a2dAutomatic Updater<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If the key's publication date is set and is in the past, the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein key is published in the zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If the key's activation date is set and in the past, the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein key is published (regardless of publication date) and
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein used to sign the zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt></dt>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If the key's revocation date is set and in the past, and the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater key is published, then the key is revoked, and the revoked key
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater is used to sign the zone.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater If either of the key's unpublication or deletion dates are set
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater and in the past, the key is NOT published or used to sign the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater zone, regardless of any other metadata.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater</dl></div>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater</dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Specifies the TTL to be used for new DNSKEY records imported
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater into the zone from the key repository. If not specified,
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater the default is the minimum TTL value from the zone's SOA
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater record. This option is ignored when signing without
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <code class="option">-S</code>, since DNSKEY records are not imported
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater from the key repository in that case. It is also ignored if
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater there are any pre-existing DNSKEY records at the zone apex,
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater in which case new records' TTL values will be set to match
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater them.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-t</span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Print statistics at completion.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-u</span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Update NSEC/NSEC3 chain when re-signing a previously signed
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater zone. With this option, a zone signed with NSEC can be
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater switched to NSEC3, or a zone signed with NSEC3 can
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater be switch to NSEC or to NSEC3 with different parameters.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Without this option, <span><strong class="command">dnssec-signzone</strong></span> will
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater retain the existing chain when re-signing.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Sets the debugging level.
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater </p></dd>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dt><span class="term">-x</span></dt>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Only sign the DNSKEY RRset with key-signing keys, and omit
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater signatures from zone-signing keys. (This is similar to the
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <span><strong class="command">dnskey-ksk-only yes;</strong></span> zone option in
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater <span><strong class="command">named</strong></span>.)
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater </p></dd>
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater<dt><span class="term">-z</span></dt>
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater<dd><p>
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater Ignore KSK flag on key when determining what to sign. This
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater causes KSK-flagged keys to sign all records, not just the
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater DNSKEY RRset. (This is similar to the
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <span><strong class="command">update-check-ksk no;</strong></span> zone option in
2895f101b5585a19015ac2c2c1e1812ac467fa12Automatic Updater <span><strong class="command">named</strong></span>.)
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater </p></dd>
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater<dt><span class="term">-3 <em class="replaceable"><code>salt</code></em></span></dt>
a3f8c8e20780e488141d200acdfea6c5f3303513Automatic Updater<dd><p>
0a7ed88633a680bb881868b75ded4d09a7bbbc50Automatic Updater Generate an NSEC3 chain with the given hex encoded salt.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein A dash (<em class="replaceable"><code>salt</code></em>) can
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein be used to indicate that no salt is to be used when generating the NSEC3 chain.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<dt><span class="term">-H <em class="replaceable"><code>iterations</code></em></span></dt>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<dd><p>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater When generating an NSEC3 chain, use this many interations. The
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater default is 10.
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater </p></dd>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<dt><span class="term">-A</span></dt>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<dd>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<p>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater When generating an NSEC3 chain set the OPTOUT flag on all
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater NSEC3 records and do not generate NSEC3 records for insecure
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein delegations.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Using this option twice (i.e., <code class="option">-AA</code>)
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater turns the OPTOUT flag off for all records. This is useful
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater when using the <code class="option">-u</code> option to modify an NSEC3
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater chain which previously had OPTOUT set.
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater </p>
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater</dd>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater<dt><span class="term">zonefile</span></dt>
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater<dd><p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The file containing the zone to be signed.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p></dd>
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater<dt><span class="term">key</span></dt>
8de0d8a6905e397ed0a26054815420685f9b435eAutomatic Updater<dd><p>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater Specify which keys should be used to sign the zone. If
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater no keys are specified, then the zone will be examined
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater for DNSKEY records at the zone apex. If these are found and
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein there are matching private keys, in the current directory,
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater then these will be used for signing.
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater </p></dd>
66fec05962ae85e63c4aa568d44a962db5bbc902Automatic Updater</dl></div>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater</div>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater<div class="refsect1" lang="en">
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater<a name="id2544896"></a><h2>EXAMPLE</h2>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater<p>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater The following command signs the <strong class="userinput"><code>example.com</code></strong>
66fec05962ae85e63c4aa568d44a962db5bbc902Automatic Updater zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
66fec05962ae85e63c4aa568d44a962db5bbc902Automatic Updater (Kexample.com.+003+17247). Because the <span><strong class="command">-S</strong></span> option
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater is not being used, the zone's keys must be in the master file
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater (<code class="filename">db.example.com</code>). This invocation looks
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater for <code class="filename">dsset</code> files, in the current directory,
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater so that DS records can be imported from them (<span><strong class="command">-g</strong></span>).
66fec05962ae85e63c4aa568d44a962db5bbc902Automatic Updater </p>
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic UpdaterKexample.com.+003+17247
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updaterdb.example.com.signed
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater%</pre>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater<p>
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater the file <code class="filename">db.example.com.signed</code>. This
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater file should be referenced in a zone statement in a
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater <code class="filename">named.conf</code> file.
f3d1a0ba5228251d902a6acf3c8b05cb6842f992Automatic Updater </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein This example re-signs a previously signed zone with default parameters.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein The private keys are assumed to be in the current directory.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<pre class="programlisting">% cp db.example.com.signed db.example.com
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein% dnssec-signzone -o example.com db.example.com
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrewsdb.example.com.signed
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews%</pre>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews</div>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews<div class="refsect1" lang="en">
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews<a name="id2545019"></a><h2>SEE ALSO</h2>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <em class="citetitle">RFC 4033</em>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </p>
be6c1c506161e6f45fcff5d0425f78801bc267c1Automatic Updater</div>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<div class="refsect1" lang="en">
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<a name="id2545044"></a><h2>AUTHOR</h2>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews<p><span class="corpauthor">Internet Systems Consortium</span>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater </p>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater</div>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater</div></body>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater</html>
3b2c6af63e0367c6eabe0a21ca23841ca87cd22fAutomatic Updater