dnssec-signzone.html revision 6ea2385360e9e2167e65f9286447da9eea189457
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington - Copyright (C) 2004-2009, 2011-2013 Internet Systems Consortium, Inc. ("ISC")
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews - Copyright (C) 2000-2003 Internet Software Consortium.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington - Permission to use, copy, modify, and/or distribute this software for any
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington - purpose with or without fee is hereby granted, provided that the above
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington - copyright notice and this permission notice appear in all copies.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
dafcb997e390efa4423883dafd100c975c4095d6Mark Andrews - PERFORMANCE OF THIS SOFTWARE.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF"><div class="refentry" lang="en">
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-L <em class="replaceable"><code>serial</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-P</code>] [<code class="option">-p</code>] [<code class="option">-R</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-X <em class="replaceable"><code>extended end-time</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<a name="id2543633"></a><h2>DESCRIPTION</h2>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<p><span><strong class="command">dnssec-signzone</strong></span>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington signs a zone. It generates
c40265eba0c99708887d68e67901924065ba2514Brian Wellington NSEC and RRSIG records and produces a signed version of the
c40265eba0c99708887d68e67901924065ba2514Brian Wellington zone. The security status of delegations from the signed zone
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson (that is, whether the child zones are secure or not) is
bca7f81db58d4803fb6d8d352132445cf61eb1acMark Andrews determined by the presence or absence of a
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="filename">keyset</code> file for each child zone.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Verify all generated signatures.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Specifies the DNS class of the zone.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Compatibility mode: Generate a
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington file in addition to
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington when signing a zone, for use by older versions of
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <span><strong class="command">dnssec-signzone</strong></span>.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Look for <code class="filename">dsset-</code> or
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="filename">keyset-</code> files in <code class="option">directory</code>.
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson Output only those record types automatically managed by
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson <span><strong class="command">dnssec-signzone</strong></span>, i.e. RRSIG, NSEC,
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson NSEC3 and NSEC3PARAM records. If smart signing
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson (<code class="option">-S</code>) is used, DNSKEY records are also
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson included. The resulting file can be included in the original
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson zone file with <span><strong class="command">$INCLUDE</strong></span>. This option
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson cannot be combined with <code class="option">-O raw</code>,
a26ad011f382d12058478704cb5e90e6f4366d01Andreas Gustafsson <code class="option">-O map</code>, or serial number updating.
92551304a9abff9284de5b79a48e83d781989339Mark Andrews<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
92551304a9abff9284de5b79a48e83d781989339Mark Andrews When applicable, specifies the hardware to use for
92551304a9abff9284de5b79a48e83d781989339Mark Andrews cryptographic operations, such as a secure key store used
92551304a9abff9284de5b79a48e83d781989339Mark Andrews for signing.
92551304a9abff9284de5b79a48e83d781989339Mark Andrews When BIND is built with OpenSSL PKCS#11 support, this defaults
92551304a9abff9284de5b79a48e83d781989339Mark Andrews to the string "pkcs11", which identifies an OpenSSL engine
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews that can drive a cryptographic accelerator or hardware service
e9359db5e958bf05f9b9c5fe3c27d533f0f05550Mark Andrews module. When BIND is built with native PKCS#11 cryptography
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews (--enable-native-pkcs11), it defaults to the path of the PKCS#11
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews provider library specified via "--with-pkcs11".
7791dd06ea69d0fb2494788ad4c24d568f40bcdfMark Andrews Generate DS records for child zones from
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington file. Existing DS records will be removed.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Key repository: Specify a directory to search for DNSSEC keys.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington If not specified, defaults to the current directory.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Treat specified key as a key signing key ignoring any
c40265eba0c99708887d68e67901924065ba2514Brian Wellington key flags. This option may be specified multiple times.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Generate a DLV set in addition to the key (DNSKEY) and DS sets.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington The domain is appended to the name of the records.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Specify the date and time when the generated RRSIG records
c40265eba0c99708887d68e67901924065ba2514Brian Wellington become valid. This can be either an absolute or relative
c40265eba0c99708887d68e67901924065ba2514Brian Wellington time. An absolute start time is indicated by a number
c40265eba0c99708887d68e67901924065ba2514Brian Wellington in YYYYMMDDHHMMSS notation; 20000530144500 denotes
c40265eba0c99708887d68e67901924065ba2514Brian Wellington 14:45:00 UTC on May 30th, 2000. A relative start time is
c40265eba0c99708887d68e67901924065ba2514Brian Wellington indicated by +N, which is N seconds from the current time.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington If no <code class="option">start-time</code> is specified, the current
c40265eba0c99708887d68e67901924065ba2514Brian Wellington time minus 1 hour (to allow for clock skew) is used.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Specify the date and time when the generated RRSIG records
c40265eba0c99708887d68e67901924065ba2514Brian Wellington expire. As with <code class="option">start-time</code>, an absolute
c40265eba0c99708887d68e67901924065ba2514Brian Wellington time is indicated in YYYYMMDDHHMMSS notation. A time relative
c40265eba0c99708887d68e67901924065ba2514Brian Wellington to the start time is indicated with +N, which is N seconds from
17cb8353e999e3294e6619613f401af3f7b1540cMark Andrews the start time. A time relative to the current time is
c40265eba0c99708887d68e67901924065ba2514Brian Wellington indicated with now+N. If no <code class="option">end-time</code> is
c40265eba0c99708887d68e67901924065ba2514Brian Wellington specified, 30 days from the start time is used as a default.
c40265eba0c99708887d68e67901924065ba2514Brian Wellington <code class="option">end-time</code> must be later than
c40265eba0c99708887d68e67901924065ba2514Brian Wellington<dt><span class="term">-X <em class="replaceable"><code>extended end-time</code></em></span></dt>
c40265eba0c99708887d68e67901924065ba2514Brian Wellington Specify the date and time when the generated RRSIG records
c40265eba0c99708887d68e67901924065ba2514Brian Wellington for the DNSKEY RRset will expire. This is to be used in cases
c40265eba0c99708887d68e67901924065ba2514Brian Wellington when the DNSKEY signatures need to persist longer than
signatures on other records; e.g., when the private component
<span><strong class="command">"raw"</strong></span>, and <span><strong class="command">"map"</strong></span>.
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
and <span><strong class="command">"map"</strong></span>, <span><strong class="command">"raw"</strong></span>,
Kexample.com.+003+17247