200N/A - Copyright (C) 2000-2015 Internet Systems Consortium, Inc. ("ISC") 200N/A - This Source Code Form is subject to the terms of the Mozilla Public 200N/A - License, v. 2.0. If a copy of the MPL was not distributed with this 200N/A<
meta http-
equiv="Content-Type" content="text/html; charset=ISO-8859-1">
200N/A<
title>dnssec-checkds</
title>
200N/A<
meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
200N/A<
link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
200N/A<
body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
200N/A<
table width="100%" summary="Navigation header">
200N/A<
tr><
th colspan="3" align="center"><
span class="application">dnssec-checkds</
span></
th></
tr>
5452N/A<
td width="20%" align="left">
5852N/A<
th width="60%" align="center">Manual pages</
th>
844N/A<
div class="refnamediv">
903N/A<
p><
span class="application">dnssec-checkds</
span> — DNSSEC delegation consistency checking tool</
p>
200N/A<
div class="refsynopsisdiv">
200N/A<
div class="cmdsynopsis"><
p><
code class="command">dnssec-checkds</
code> [<
code class="option">-l <
em class="replaceable"><
code>domain</
code></
em></
code>] [<
code class="option">-f <
em class="replaceable"><
code>file</
code></
em></
code>] [<
code class="option">-d <
em class="replaceable"><
code>dig path</
code></
em></
code>] [<
code class="option">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
code>] {zone}</
p></
div>
5776N/A<
div class="cmdsynopsis"><
p><
code class="command">dnssec-dsfromkey</
code> [<
code class="option">-l <
em class="replaceable"><
code>domain</
code></
em></
code>] [<
code class="option">-f <
em class="replaceable"><
code>file</
code></
em></
code>] [<
code class="option">-d <
em class="replaceable"><
code>dig path</
code></
em></
code>] [<
code class="option">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
code>] {zone}</
p></
div>
200N/A<
a name="id-1.14.5.7"></
a><
h2>DESCRIPTION</
h2>
5776N/A<
p><
span class="command"><
strong>dnssec-checkds</
strong></
span>
200N/A verifies the correctness of Delegation Signer (DS) or DNSSEC
5852N/A Lookaside Validation (DLV) resource records for keys in a specified
206N/A<
a name="id-1.14.5.8"></
a><
h2>OPTIONS</
h2>
200N/A<
div class="variablelist"><
dl class="variablelist">
206N/A<
dt><
span class="term">-f <
em class="replaceable"><
code>file</
code></
em></
span></
dt>
1625N/A If a <
code class="option">file</
code> is specified, then the zone is
5852N/A read from that file to find the DNSKEY records. If not,
206N/A then the DNSKEY records for the zone are looked up in the DNS.
5852N/A<
dt><
span class="term">-l <
em class="replaceable"><
code>domain</
code></
em></
span></
dt>
5852N/A Check for a DLV record in the specified lookaside domain,
5852N/A instead of checking for a DS record in the zone's parent.
4203N/A<
dt><
span class="term">-d <
em class="replaceable"><
code>dig path</
code></
em></
span></
dt>
3865N/A Specifies a path to a <
span class="command"><
strong>dig</
strong></
span> binary. Used
3865N/A<
dt><
span class="term">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
span></
dt>
5852N/A Specifies a path to a <
span class="command"><
strong>dnssec-dsfromkey</
strong></
span> binary.
3865N/A<
a name="id-1.14.5.9"></
a><
h2>SEE ALSO</
h2>
5852N/A<
p><
span class="citerefentry"><
span class="refentrytitle">dnssec-dsfromkey</
span>(8)</
span>,
5852N/A <
span class="citerefentry"><
span class="refentrytitle">dnssec-keygen</
span>(8)</
span>,
5852N/A <
span class="citerefentry"><
span class="refentrytitle">dnssec-signzone</
span>(8)</
span>,
5852N/A<
table width="100%" summary="Navigation footer">
5852N/A<
td width="40%" align="left">
5852N/A<
td width="40%" align="left" valign="top">delv�</
td>
5852N/A<
td width="40%" align="right" valign="top">�<
span class="application">dnssec-coverage</
span>