man.dnssec-checkds.html revision 52cc3bd9c1f5f6123e7b30f65a110a8c3557a43c
da9cd70c94407d05ad340bdcf620adb579b21e36sin - Copyright (C) 2004-2013 Internet Systems Consortium, Inc. ("ISC")
da9cd70c94407d05ad340bdcf620adb579b21e36sin - Copyright (C) 2000-2003 Internet Software Consortium.
da9cd70c94407d05ad340bdcf620adb579b21e36sin - Permission to use, copy, modify, and/or distribute this software for any
da9cd70c94407d05ad340bdcf620adb579b21e36sin - purpose with or without fee is hereby granted, provided that the above
da9cd70c94407d05ad340bdcf620adb579b21e36sin - copyright notice and this permission notice appear in all copies.
8cf870d281dc8c242f083d14dfef05f24aa5fceeJnRouvignac - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8cf870d281dc8c242f083d14dfef05f24aa5fceeJnRouvignac - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
da9cd70c94407d05ad340bdcf620adb579b21e36sin - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
da9cd70c94407d05ad340bdcf620adb579b21e36sin - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
da9cd70c94407d05ad340bdcf620adb579b21e36sin - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
da9cd70c94407d05ad340bdcf620adb579b21e36sin - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8cf870d281dc8c242f083d14dfef05f24aa5fceeJnRouvignac - PERFORMANCE OF THIS SOFTWARE.
8cf870d281dc8c242f083d14dfef05f24aa5fceeJnRouvignac<!-- $Id$ -->
da9cd70c94407d05ad340bdcf620adb579b21e36sin<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<link rel="next" href="man.dnssec-coverage.html" title="dnssec-coverage">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
da9cd70c94407d05ad340bdcf620adb579b21e36sin<tr><th colspan="3" align="center"><span class="application">dnssec-checkds</span></th></tr>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-coverage.html">Next</a>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<a name="man.dnssec-checkds"></a><div class="titlepage"></div>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<p><span class="application">dnssec-checkds</span> — A DNSSEC delegation consistency checking tool.</p>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<div class="cmdsynopsis"><p><code class="command">dnssec-checkds</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
da9cd70c94407d05ad340bdcf620adb579b21e36sin<p><span><strong class="command">dnssec-checkds</strong></span>
da9cd70c94407d05ad340bdcf620adb579b21e36sin verifies the correctness of Delegation Signer (DS) or DNSSEC
da9cd70c94407d05ad340bdcf620adb579b21e36sin Lookaside Validation (DLV) resource records for keys in a specified
da9cd70c94407d05ad340bdcf620adb579b21e36sin<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
da9cd70c94407d05ad340bdcf620adb579b21e36sin If a <code class="option">file</code> is specified, then the zone is
da9cd70c94407d05ad340bdcf620adb579b21e36sin read from that file to find the DNSKEY records. If not,
da9cd70c94407d05ad340bdcf620adb579b21e36sin then the DNSKEY records for the zone are looked up in the DNS.
da9cd70c94407d05ad340bdcf620adb579b21e36sin<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
For example, to check for DLV records for "example.com"