dnssec-signzone.html revision 89da2a56413ba6294315bdde04f7547b9d71b062
689023771c563d8660e45d439a207e06e96de28fMark Andrews<!--
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater - Copyright (C) 2004, 2005 Internet Systems Consortium, Inc. ("ISC")
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - Copyright (C) 2001-2003 Internet Software Consortium.
4a14ce5ba00ab7bc55c99ffdcf59c7a4ab902721Automatic Updater -
689023771c563d8660e45d439a207e06e96de28fMark Andrews - Permission to use, copy, modify, and distribute this software for any
689023771c563d8660e45d439a207e06e96de28fMark Andrews - purpose with or without fee is hereby granted, provided that the above
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - copyright notice and this permission notice appear in all copies.
689023771c563d8660e45d439a207e06e96de28fMark Andrews -
689023771c563d8660e45d439a207e06e96de28fMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
689023771c563d8660e45d439a207e06e96de28fMark Andrews - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
689023771c563d8660e45d439a207e06e96de28fMark Andrews - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
689023771c563d8660e45d439a207e06e96de28fMark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
689023771c563d8660e45d439a207e06e96de28fMark Andrews - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
689023771c563d8660e45d439a207e06e96de28fMark Andrews - PERFORMANCE OF THIS SOFTWARE.
eea6be913f9928255cab5f58ff27da41c1e8e23aAutomatic Updater-->
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<!-- $Id: dnssec-signzone.html,v 1.16 2005/04/03 03:31:32 marka Exp $ -->
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
e21a2904f02a03fa06b6db04d348f65fe9c67b2bMark Andrews<HTML
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><HEAD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><TITLE
4abdfc917e6635a7c81d1f931a0c79227e72d025Mark Andrews>dnssec-signzone</TITLE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><META
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="GENERATOR"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCONTENT="Modular DocBook HTML Stylesheet Version 1.79"></HEAD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><BODY
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFENTRY"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinBGCOLOR="#FFFFFF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinTEXT="#000000"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinLINK="#0000FF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinVLINK="#840084"
65ad89971ee9973074cd11c207af92bf5440df01Automatic UpdaterALINK="#0000FF"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H1
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN1"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="APPLICATION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone</SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></H1
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFNAMEDIV"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN9"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>Name</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="APPLICATION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone</SPAN
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>&nbsp;--&nbsp;DNSSEC zone signing tool</DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFSYNOPSISDIV"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN13"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H2
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>Synopsis</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="COMMAND"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-a</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
65ad89971ee9973074cd11c207af92bf5440df01Automatic UpdaterCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-c <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>class</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>-d <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>directory</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
00124ad0406365d39f4b2d1011ef6a76706e9df0Mark Andrews></CODE
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-e <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>end-time</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-f <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>output-file</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-g</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-h</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>-k <TT
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic UpdaterCLASS="REPLACEABLE"
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater><I
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater>key</I
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater></TT
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater></CODE
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater>] [<CODE
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic UpdaterCLASS="OPTION"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>-l <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>domain</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-i <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>interval</I
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-j <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews><I
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews>jitter</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews>-n <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>nthreads</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-o <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews>origin</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-p</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>-r <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>randomdev</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-s <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>start-time</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-t</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-v <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>level</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
4a71c59d2bf32585c5dd18f4630d5f10e56a1ab3Automatic Updater></CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] [<CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-z</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>] {zonefile} [key...]</P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFSECT1"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN69"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H2
517ae3de96aaf870049c52f1224e38a85fe7f21aAutomatic Updater>DESCRIPTION</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> <B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="COMMAND"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> signs a zone. It generates
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein NSEC and RRSIG records and produces a signed version of the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone. The security status of delegations from the signed zone
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews (that is, whether the child zones are secure or not) is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein determined by the presence or absence of a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>keyset</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> file for each child zone.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
689023771c563d8660e45d439a207e06e96de28fMark AndrewsCLASS="REFSECT1"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN74"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>OPTIONS</H2
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews><P
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews></P
89bc48260b64a8859ae717e9e5bae380e275fef4Mark Andrews><DIV
89bc48260b64a8859ae717e9e5bae380e275fef4Mark AndrewsCLASS="VARIABLELIST"
89bc48260b64a8859ae717e9e5bae380e275fef4Mark Andrews><DL
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
79cf9524b15ca65f55fd6913e6cf01b5581c588aAutomatic Updater>-a</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Verify all generated signatures.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
276e28f813ffef042d5a6e9f3373ef4e2ad37996Mark Andrews><DT
276e28f813ffef042d5a6e9f3373ef4e2ad37996Mark Andrews>-c <TT
538a83db7509d598da95a93bd7b74ef3112123a4Mark AndrewsCLASS="REPLACEABLE"
538a83db7509d598da95a93bd7b74ef3112123a4Mark Andrews><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>class</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
3a3705ef7747327df182bf8d009333d2472253d5Mark Andrews></DT
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><DD
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><P
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews> Specifies the DNS class of the zone.
22c71c7b86fa57a19f7df0da4222eb8593e6ad12Mark Andrews </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-k <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>key</I
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Treat specified key as a key signing key ignoring any
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein key flags. This option may be specified multiple times.
f051d76c87e055c6ea3879e0c97a76609df915ccMark Andrews </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-l <TT
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark AndrewsCLASS="REPLACEABLE"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><I
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>domain</I
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></TT
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></DT
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><DD
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><P
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater> Generate a DLV set in addition to the key (DNSKEY) and DS sets.
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater The domain is appended to the name of the records.
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater </P
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></DD
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><DT
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews>-d <TT
1586d8cbac5d73031716561386f60758c6c332d5Mark AndrewsCLASS="REPLACEABLE"
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews><I
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews>directory</I
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Look for <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews>keyset</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> files in
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews <CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>directory</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> as the directory
083a5588a3488b6335ee7bafa505d00644c7c58dMark Andrews </P
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
763a2f8ca55318aedb0dc0e5b1d35b53fe28c7d5Mark Andrews>-g</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Generate DS records for child zones from keyset files.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Existing DS records will be removed.
7526edc7677371c366232de5f39a678b7dcda747Mark Andrews </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater><DT
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater>-s <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>start-time</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
689023771c563d8660e45d439a207e06e96de28fMark Andrews><DD
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Specify the date and time when the generated RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein become valid. This can be either an absolute or relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time. An absolute start time is indicated by a number
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein in YYYYMMDDHHMMSS notation; 20000530144500 denotes
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein 14:45:00 UTC on May 30th, 2000. A relative start time is
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein indicated by +N, which is N seconds from the current time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein If no <CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>start-time</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> is specified, the current
aeb7938001b22e811a910e1b36cdf452f9193865Automatic Updater time minus 1 hour (to allow for clock skew) is used.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
aeb7938001b22e811a910e1b36cdf452f9193865Automatic Updater></DD
aeb7938001b22e811a910e1b36cdf452f9193865Automatic Updater><DT
aeb7938001b22e811a910e1b36cdf452f9193865Automatic Updater>-e <TT
aeb7938001b22e811a910e1b36cdf452f9193865Automatic UpdaterCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>end-time</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Specify the date and time when the generated RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein expire. As with <CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>start-time</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>, an absolute
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein time is indicated in YYYYMMDDHHMMSS notation. A time relative
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein to the start time is indicated with +N, which is N seconds from
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the start time. A time relative to the current time is
0284e57b9b9dfaf2517a2cc3282ecf766b8ad075Automatic Updater indicated with now+N. If no <CODE
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic UpdaterCLASS="OPTION"
6bf6622b7b9053dc52527478473b572f042c4b5bMark Andrews>end-time</CODE
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews> is
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews specified, 30 days from the start time is used as a default.
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater </P
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater></DD
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater><DT
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater>-f <TT
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic UpdaterCLASS="REPLACEABLE"
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater><I
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater>output-file</I
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater></TT
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> The name of the output file containing the signed zone. The
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein default is to append <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>.signed</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> to the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein input file.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-h</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Prints a short summary of the options and arguments to
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="COMMAND"
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater>dnssec-signzone</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-i <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>interval</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
689023771c563d8660e45d439a207e06e96de28fMark Andrews></DT
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
689023771c563d8660e45d439a207e06e96de28fMark Andrews> When a previously signed zone is passed as input, records
689023771c563d8660e45d439a207e06e96de28fMark Andrews may be resigned. The <CODE
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark AndrewsCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>interval</CODE
689023771c563d8660e45d439a207e06e96de28fMark Andrews> option
689023771c563d8660e45d439a207e06e96de28fMark Andrews specifies the cycle interval as an offset from the current
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews time (in seconds). If a RRSIG record expires after the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein cycle interval, it is retained. Otherwise, it is considered
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater to be expiring soon, and it will be replaced.
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater </P
689023771c563d8660e45d439a207e06e96de28fMark Andrews><P
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews> The default cycle interval is one quarter of the difference
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein between the signature end and start times. So if neither
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews <CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>end-time</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> or <CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="OPTION"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>start-time</CODE
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein are specified, <B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="COMMAND"
689023771c563d8660e45d439a207e06e96de28fMark Andrews>dnssec-signzone</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> generates
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein signatures that are valid for 30 days, with a cycle
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein interval of 7.5 days. Therefore, if any existing RRSIG records
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein are due to expire in less than 7.5 days, they would be
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein replaced.
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews </P
47012ae6dbf18a2503d7b33c1c9583dc38625cb7Mark Andrews></DD
89bc48260b64a8859ae717e9e5bae380e275fef4Mark Andrews><DT
89bc48260b64a8859ae717e9e5bae380e275fef4Mark Andrews></DT
89bc48260b64a8859ae717e9e5bae380e275fef4Mark Andrews><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
79cf9524b15ca65f55fd6913e6cf01b5581c588aAutomatic Updater> When signing a zone with a fixed signature lifetime, all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein RRSIG records issued at the time of signing expires
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein simultaneously. If the zone is incrementally signed, i.e.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein a previously signed zone is passed as input to the signer,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein all expired signatures has to be regenerated at about the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein same time. The <CODE
276e28f813ffef042d5a6e9f3373ef4e2ad37996Mark AndrewsCLASS="OPTION"
276e28f813ffef042d5a6e9f3373ef4e2ad37996Mark Andrews>jitter</CODE
538a83db7509d598da95a93bd7b74ef3112123a4Mark Andrews> option specifies a
538a83db7509d598da95a93bd7b74ef3112123a4Mark Andrews jitter window that will be used to randomize the signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein expire time, thus spreading incremental signature
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein regeneration over time.
3a3705ef7747327df182bf8d009333d2472253d5Mark Andrews </P
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><P
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews> Signature lifetime jitter also to some extent benefits
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews validators and servers by spreading out cache expiration,
22c71c7b86fa57a19f7df0da4222eb8593e6ad12Mark Andrews i.e. if large numbers of RRSIGs don't expire at the same time
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein from all caches there will be less congestion than if all
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein validators need to refetch at mostly the same time.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-n <TT
689023771c563d8660e45d439a207e06e96de28fMark AndrewsCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews>ncpus</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
f051d76c87e055c6ea3879e0c97a76609df915ccMark Andrews><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Specifies the number of threads to use. By default, one
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein thread is started for each detected CPU.
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews </P
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></DD
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><DT
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>-o <TT
65ad89971ee9973074cd11c207af92bf5440df01Automatic UpdaterCLASS="REPLACEABLE"
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><I
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater>origin</I
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></TT
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater></DT
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><DD
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater><P
65ad89971ee9973074cd11c207af92bf5440df01Automatic Updater> The zone origin. If not specified, the name of the zone file
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews is assumed to be the origin.
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews </P
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews></DD
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews><DT
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews>-p</DT
1586d8cbac5d73031716561386f60758c6c332d5Mark Andrews><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Use pseudo-random data when signing the zone. This is faster,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein but less secure, than using real random data. This option
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein may be useful when signing large zones or when the entropy
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews source is limited.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark Andrews></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-r <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
083a5588a3488b6335ee7bafa505d00644c7c58dMark Andrews><I
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater>randomdev</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
763a2f8ca55318aedb0dc0e5b1d35b53fe28c7d5Mark Andrews></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Specifies the source of randomness. If the operating
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein system does not provide a <TT
7526edc7677371c366232de5f39a678b7dcda747Mark AndrewsCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>/dev/random</TT
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater>
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater or equivalent device, the default source of randomness
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein is keyboard input. <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>randomdev</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> specifies
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein the name of a character device or file containing random
689023771c563d8660e45d439a207e06e96de28fMark Andrews data to be used instead of the default. The special value
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>keyboard</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> indicates that keyboard
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein input should be used.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-t</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Print statistics at completion.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>-v <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REPLACEABLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>level</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Sets the debugging level.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
6bf6622b7b9053dc52527478473b572f042c4b5bMark Andrews></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews>-z</DT
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><DD
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Ignore KSK flag on key when determining what to sign.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>zonefile</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> The file containing the zone to be signed.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein Sets the debugging level.
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DT
8a8d38eb8e5f853835df2f6799ce0d3d7ecf8be6Automatic Updater>key</DT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> The keys used to sign the zone. If no keys are specified, the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein default all zone keys that have private key files in the
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein current directory.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DD
689023771c563d8660e45d439a207e06e96de28fMark Andrews></DL
689023771c563d8660e45d439a207e06e96de28fMark Andrews></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFSECT1"
3a3705ef7747327df182bf8d009333d2472253d5Mark Andrews><A
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark AndrewsNAME="AEN190"
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews></A
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark Andrews><H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>EXAMPLE</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> The following command signs the <KBD
3b4098640dd85040270f39b9a5ee5e22de99d3d6Mark AndrewsCLASS="USERINPUT"
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater>example.com</KBD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein zone with the DSA key generated in the <B
68b30890ebd441a6a1ae3fdf71744d07d02cd030Mark AndrewsCLASS="COMMAND"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-keygen</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein man page. The zone's keys must be in the zone. If there are
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
f4429c1c31ec32f05125baab1adcc4f09863f7afMark Andrews>keyset</TT
f4429c1c31ec32f05125baab1adcc4f09863f7afMark Andrews> files associated with child zones,
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater they must be in the current directory.
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater <KBD
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic UpdaterCLASS="USERINPUT"
d060d8669f5558690e7faf4a1c12fe5c02a7c60dAutomatic Updater>example.com</KBD
083a5588a3488b6335ee7bafa505d00644c7c58dMark Andrews>, the following command would be
089c63b69cdf6803aa8901aae3f2fbae58969511Automatic Updater issued:
4f6469885c3d66367e3f8fb94e1f3c66115990b0Mark Andrews </P
763a2f8ca55318aedb0dc0e5b1d35b53fe28c7d5Mark Andrews><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> <KBD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="USERINPUT"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone -o example.com db.example.com Kexample.com.+003+26160</KBD
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>
7526edc7677371c366232de5f39a678b7dcda747Mark Andrews </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater> The command would print a string of the form:
d9c707589ade5d69fb59b6837555adc4cd24d34fAutomatic Updater </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> In this example, <B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="COMMAND"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-signzone</B
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> creates
689023771c563d8660e45d439a207e06e96de28fMark Andrews the file <TT
689023771c563d8660e45d439a207e06e96de28fMark AndrewsCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>db.example.com.signed</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>. This file
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein should be referenced in a zone statement in a
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="FILENAME"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>named.conf</TT
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> file.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
eea6be913f9928255cab5f58ff27da41c1e8e23aAutomatic UpdaterCLASS="REFSECT1"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN204"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>SEE ALSO</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> <SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="CITEREFENTRY"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFENTRYTITLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>dnssec-keygen</SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>(8)</SPAN
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>,
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein <I
6bf6622b7b9053dc52527478473b572f042c4b5bMark AndrewsCLASS="CITETITLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>BIND 9 Administrator Reference Manual</I
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater>,
731cc132f22dbc9e0ecd7035dce314a61076d31bAutomatic Updater <I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="CITETITLE"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>RFC 2535</I
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>.
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinCLASS="REFSECT1"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><A
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob AusteinNAME="AEN212"
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></A
eea6be913f9928255cab5f58ff27da41c1e8e23aAutomatic Updater><H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>AUTHOR</H2
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein><P
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein> Internet Systems Consortium
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein </P
eea6be913f9928255cab5f58ff27da41c1e8e23aAutomatic Updater></DIV
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein></BODY
1224c3b69b3d18f7127aa042644936af25a2d679Mark Andrews></HTML
60e5e10f8d2e2b0c41e8abad38cacd867caa6ab2Rob Austein>
d71e2e0c61df16ff37c9934c371a4a60c08974f7Mark Andrews