<
link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
<
body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
<
table width="100%" summary="Navigation header">
<
tr><
th colspan="3" align="center"><
span class="application">dnssec-checkds</
span></
th></
tr>
<
td width="20%" align="left">
<
th width="60%" align="center">Manual pages</
th>
<
span class="application">dnssec-checkds</
span>
— DNSSEC delegation consistency checking tool
<
div class="refsynopsisdiv">
<
div class="cmdsynopsis"><
p>
<
code class="command">dnssec-checkds</
code>
[<
code class="option">-l <
em class="replaceable"><
code>domain</
code></
em></
code>]
[<
code class="option">-f <
em class="replaceable"><
code>file</
code></
em></
code>]
[<
code class="option">-d <
em class="replaceable"><
code>dig path</
code></
em></
code>]
[<
code class="option">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
code>]
<
div class="cmdsynopsis"><
p>
<
code class="command">dnssec-dsfromkey</
code>
[<
code class="option">-l <
em class="replaceable"><
code>domain</
code></
em></
code>]
[<
code class="option">-f <
em class="replaceable"><
code>file</
code></
em></
code>]
[<
code class="option">-d <
em class="replaceable"><
code>dig path</
code></
em></
code>]
[<
code class="option">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
code>]
<
a name="id-1.14.7.7"></
a><
h2>DESCRIPTION</
h2>
<
p><
span class="command"><
strong>dnssec-checkds</
strong></
span>
verifies the correctness of Delegation Signer (DS) or DNSSEC
Lookaside Validation (DLV) resource records for keys in a specified
<
a name="id-1.14.7.8"></
a><
h2>OPTIONS</
h2>
<
div class="variablelist"><
dl class="variablelist">
<
dt><
span class="term">-f <
em class="replaceable"><
code>file</
code></
em></
span></
dt>
If a <
code class="option">file</
code> is specified, then the zone is
read from that file to find the DNSKEY records. If not,
then the DNSKEY records for the zone are looked up in the DNS.
<
dt><
span class="term">-l <
em class="replaceable"><
code>domain</
code></
em></
span></
dt>
Check for a DLV record in the specified lookaside domain,
instead of checking for a DS record in the zone's parent.
<
dt><
span class="term">-d <
em class="replaceable"><
code>dig path</
code></
em></
span></
dt>
Specifies a path to a <
span class="command"><
strong>dig</
strong></
span> binary. Used
<
dt><
span class="term">-D <
em class="replaceable"><
code>dsfromkey path</
code></
em></
span></
dt>
Specifies a path to a <
span class="command"><
strong>dnssec-dsfromkey</
strong></
span> binary.
<
a name="id-1.14.7.9"></
a><
h2>SEE ALSO</
h2>
<
p><
span class="citerefentry">
<
span class="refentrytitle">dnssec-dsfromkey</
span>(8)
<
span class="citerefentry">
<
span class="refentrytitle">dnssec-keygen</
span>(8)
<
span class="citerefentry">
<
span class="refentrytitle">dnssec-signzone</
span>(8)
<
table width="100%" summary="Navigation footer">
<
td width="40%" align="left">
<
td width="20%" align="center"><
a accesskey="u" href="Bv9ARM.ch13.html">Up</
a></
td>
<
td width="40%" align="left" valign="top">nslookup�</
td>
<
td width="20%" align="center"><
a accesskey="h" href="Bv9ARM.html">Home</
a></
td>
<
td width="40%" align="right" valign="top">�<
span class="application">dnssec-coverage</
span>