dnssec-checkds.docbook revision 024cf50d122a16a3ce190692d3669ecee47c23aa
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN"
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd"
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek [<!ENTITY mdash "&#8212;">]>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek<!--
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - Copyright (C) 2012, 2013 Internet Systems Consortium, Inc. ("ISC")
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek -
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - Permission to use, copy, modify, and/or distribute this software for any
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - purpose with or without fee is hereby granted, provided that the above
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - copyright notice and this permission notice appear in all copies.
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek -
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek - PERFORMANCE OF THIS SOFTWARE.
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek-->
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek<!-- $Id$ -->
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek<refentry id="man.dnssec-checkds">
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refentryinfo>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <date>April 11, 2012</date>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </refentryinfo>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refmeta>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refentrytitle><application>dnssec-checkds</application></refentrytitle>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <manvolnum>8</manvolnum>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refmiscinfo>BIND9</refmiscinfo>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </refmeta>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refnamediv>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refname><application>dnssec-checkds</application></refname>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refpurpose>A DNSSEC delegation consistency checking tool.</refpurpose>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </refnamediv>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <docinfo>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <copyright>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <year>2012</year>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <year>2013</year>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <holder>Internet Systems Consortium, Inc. ("ISC")</holder>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </copyright>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </docinfo>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <refsynopsisdiv>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <cmdsynopsis>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <command>dnssec-checkds</command>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-f <replaceable class="parameter">file</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg choice="req">zone</arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </cmdsynopsis>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <cmdsynopsis>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <command>dnssec-dsfromkey</command>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-f <replaceable class="parameter">file</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-d <replaceable class="parameter">dig path</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg><option>-D <replaceable class="parameter">dsfromkey path</replaceable></option></arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek <arg choice="req">zone</arg>
620033ce66f4827be9d508c77483fab0270d9869Jakub Hrozek </cmdsynopsis>
</refsynopsisdiv>
<refsect1>
<title>DESCRIPTION</title>
<para><command>dnssec-checkds</command>
verifies the correctness of Delegation Signer (DS) or DNSSEC
Lookaside Validation (DLV) resource records for keys in a specified
zone.
</para>
</refsect1>
<refsect1>
<title>OPTIONS</title>
<variablelist>
<varlistentry>
<term>-f <replaceable class="parameter">file</replaceable></term>
<listitem>
<para>
If a <option>file</option> is specified, then the zone is
read from that file to find the DNSKEY records. If not,
then the DNSKEY records for the zone are looked up in the DNS.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-l <replaceable class="parameter">domain</replaceable></term>
<listitem>
<para>
Check for a DLV record in the specified lookaside domain,
instead of checking for a DS record in the zone's parent.
For example, to check for DLV records for "example.com"
in ISC's DLV zone, use:
<command>dnssec-checkds -l dlv.isc.org example.com</command>
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-d <replaceable class="parameter">dig path</replaceable></term>
<listitem>
<para>
Specifies a path to a <command>dig</command> binary. Used
for testing.
</para>
</listitem>
</varlistentry>
<varlistentry>
<term>-D <replaceable class="parameter">dsfromkey path</replaceable></term>
<listitem>
<para>
Specifies a path to a <command>dnssec-dsfromkey</command> binary.
Used for testing.
</para>
</listitem>
</varlistentry>
</variablelist>
</refsect1>
<refsect1>
<title>SEE ALSO</title>
<para><citerefentry>
<refentrytitle>dnssec-dsfromkey</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
<citerefentry>
<refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum>
</citerefentry>,
</para>
</refsect1>
<refsect1>
<title>AUTHOR</title>
<para><corpauthor>Internet Systems Consortium</corpauthor>
</para>
</refsect1>
</refentry><!--
- Local variables:
- mode: sgml
- End:
-->