man.dnssec-checkds.html revision 8168c2873909444bdf62325b29fe118a879b22fc
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - purpose with or without fee is hereby granted, provided that the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - copyright notice and this permission notice appear in all copies.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - PERFORMANCE OF THIS SOFTWARE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- $Id$ -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="prev" href="man.delv.html" title="delv">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="next" href="man.dnssec-coverage.html" title="dnssec-coverage">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation header">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr><th colspan="3" align="center"><span class="application">dnssec-checkds</span></th></tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a accesskey="p" href="man.delv.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<th width="60%" align="center">Manual pages</th>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-coverage.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="man.dnssec-checkds"></a><div class="titlepage"></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="application">dnssec-checkds</span> — A DNSSEC delegation consistency checking tool.</p>
be1785efc04c1f3f74f021992ca53155807dba2dDavid Luna<div class="cmdsynopsis"><p><code class="command">dnssec-checkds</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
be1785efc04c1f3f74f021992ca53155807dba2dDavid Luna<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dig path</code></em></code>] [<code class="option">-D <em class="replaceable"><code>dsfromkey path</code></em></code>] {zone}</p></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span><strong class="command">dnssec-checkds</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster verifies the correctness of Delegation Signer (DS) or DNSSEC
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington Lookaside Validation (DLV) resource records for keys in a specified
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington If a <code class="option">file</code> is specified, then the zone is
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington read from that file to find the DNSKEY records. If not,
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington then the DNSKEY records for the zone are looked up in the DNS.
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington Check for a DLV record in the specified lookaside domain,
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington instead of checking for a DS record in the zone's parent.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster For example, to check for DLV records for "example.com"
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in ISC's DLV zone, use:
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">dnssec-checkds -l dlv.isc.org example.com</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-d <em class="replaceable"><code>dig path</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Specifies a path to a <span><strong class="command">dig</strong></span> binary. Used
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster for testing.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-D <em class="replaceable"><code>dsfromkey path</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Specifies a path to a <span><strong class="command">dnssec-dsfromkey</strong></span> binary.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Used for testing.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="citerefentry"><span class="refentrytitle">dnssec-dsfromkey</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington<p><span class="corpauthor">Internet Systems Consortium</span>
a6bf4d9e39eae70c6b74d0d91d35704662c84ff7Phill Cunnington<table width="100%" summary="Navigation footer">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a accesskey="p" href="man.delv.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-coverage.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="left" valign="top">delv�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="40%" align="right" valign="top">�<span class="application">dnssec-coverage</span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p style="text-align: center;">BIND 9.11.0pre-alpha</p>