man.dnssec-checkds.html revision 0da02c26a6631c25f075a8e4ac6de9e58f49a0c2
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd - Copyright (C) 2000-2016 Internet Systems Consortium, Inc. ("ISC")
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd - This Source Code Form is subject to the terms of the Mozilla Public
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd - License, v. 2.0. If a copy of the MPL was not distributed with this
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd - file, You can obtain one at http://mozilla.org/MPL/2.0/.
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<link rel="prev" href="man.nslookup.html" title="nslookup">
d229f940abfb2490dee17979e9a5ff31b7012eb5rbowen<link rel="next" href="man.dnssec-coverage.html" title="dnssec-coverage">
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<tr><th colspan="3" align="center"><span class="application">dnssec-checkds</span></th></tr>
ecc5150d35c0dc5ee5119c2717e6660fa331abbftakashi<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-coverage.html">Next</a>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<a name="man.dnssec-checkds"></a><div class="titlepage"></div>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd — DNSSEC delegation consistency checking tool
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-f <em class="replaceable"><code>file</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>]
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd <p><span class="command"><strong>dnssec-checkds</strong></span>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd verifies the correctness of Delegation Signer (DS) or DNSSEC
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd Lookaside Validation (DLV) resource records for keys in a specified
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd If a <code class="option">file</code> is specified, then the zone is
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd read from that file to find the DNSKEY records. If not,
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd then the DNSKEY records for the zone are looked up in the DNS.
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd Check for a DLV record in the specified lookaside domain,
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd instead of checking for a DS record in the zone's parent.
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd For example, to check for DLV records for "example.com"
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd in ISC's DLV zone, use:
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd <span class="command"><strong>dnssec-checkds -l dlv.isc.org example.com</strong></span>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd Specifies a path to a <span class="command"><strong>dig</strong></span> binary. Used
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd for testing.
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<dt><span class="term">-D <em class="replaceable"><code>dsfromkey path</code></em></span></dt>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd Specifies a path to a <span class="command"><strong>dnssec-dsfromkey</strong></span> binary.
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd Used for testing.
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-coverage.html">Next</a>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<td width="40%" align="right" valign="top">�<span class="application">dnssec-coverage</span>
6116c12fdd3ed06d388fe6572e50a22e9320dfa5nd<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.1b1</p>