man.dnssec-coverage.html revision 0d00a726fe3c0423fab1d6876e89b69a4afe44e2
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<!--
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson - Copyright (C) 2000-2003 Internet Software Consortium.
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews -
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - Permission to use, copy, modify, and/or distribute this software for any
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews - purpose with or without fee is hereby granted, provided that the above
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson - copyright notice and this permission notice appear in all copies.
2eeb74d1cf5355dd98f6d507a10086e16bb08c4bTinderbox User -
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
83a28ca274521e15086fc39febde507bcc4e145eMark Andrews - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - PERFORMANCE OF THIS SOFTWARE.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt-->
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<!-- $Id$ -->
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<html>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<head>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<title>dnssec-coverage</title>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<link rel="prev" href="man.dnssec-checkds.html" title="dnssec-checkds">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<link rel="next" href="man.dnssec-dsfromkey.html" title="dnssec-dsfromkey">
194e2dfffa6a167b8eef0ad11864026b423a1c30Mark Andrews</head>
194e2dfffa6a167b8eef0ad11864026b423a1c30Mark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<div class="navheader">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<table width="100%" summary="Navigation header">
c1a883f2e04d94e99c433b1f6cfd0c0338f4ed85Mark Andrews<tr><th colspan="3" align="center"><span class="application">dnssec-coverage</span></th></tr>
938440694b33cd752e9e4b71a526368b4811c177Tinderbox User<tr>
19c7b1a0293498a3e36692c59646ed6e15ffc8d0Tinderbox User<td width="20%" align="left">
0c27b3fe77ac1d5094ba3521e8142d9e7973133fMark Andrews<a accesskey="p" href="man.dnssec-checkds.html">Prev</a>�</td>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<th width="60%" align="center">Manual pages</th>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-dsfromkey.html">Next</a>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</td>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</tr>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</table>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<hr>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<div class="refentry" lang="en">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<a name="man.dnssec-coverage"></a><div class="titlepage"></div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<div class="refnamediv">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<h2>Name</h2>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<p><span class="application">dnssec-coverage</span> &#8212; checks future DNSKEY coverage for a zone</p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson</div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<div class="refsynopsisdiv">
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<h2>Synopsis</h2>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<div class="cmdsynopsis"><p><code class="command">dnssec-coverage</code> [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-l <em class="replaceable"><code>length</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>DNSKEY TTL</code></em></code>] [<code class="option">-m <em class="replaceable"><code>max TTL</code></em></code>] [<code class="option">-r <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-c <em class="replaceable"><code>compilezone path</code></em></code>] [<code class="option">-k</code>] [<code class="option">-z</code>] [zone]</p></div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<div class="refsect1" lang="en">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<a name="id2618605"></a><h2>DESCRIPTION</h2>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p><span><strong class="command">dnssec-coverage</strong></span>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein verifies that the DNSSEC keys for a given zone or a set of zones
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein have timing metadata set properly to ensure no future lapses in DNSSEC
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson coverage.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson If <code class="option">zone</code> is specified, then keys found in
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein the key repository matching that zone are scanned, and an ordered
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein list is generated of the events scheduled for that key (i.e.,
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson publication, activation, inactivation, deletion). The list of
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson events is walked in order of occurrence. Warnings are generated
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein if any event is scheduled which could cause the zone to enter a
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein state in which validation failures might occur: for example, if
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein the number of published or active keys for a given algorithm drops
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein to zero, or if a key is deleted from the zone too soon after a new
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson key is rolled, and cached data signed by the prior key has not had
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson time to expire from resolver caches.
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson </p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein If <code class="option">zone</code> is not specified, then all keys in the
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein key repository will be scanned, and all zones for which there are
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein keys will be analyzed. (Note: This method of reporting is only
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson accurate if all the zones that have keys in a given repository
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson share the same TTL parameters.)
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson </p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson</div>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<div class="refsect1" lang="en">
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<a name="id2618632"></a><h2>OPTIONS</h2>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<div class="variablelist"><dl>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson<dd><p>
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson Sets the directory in which keys can be found. Defaults to the
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson current working directory.
ddccd5811feff696ba460dabfb666ce61040f545Andreas Gustafsson </p></dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd><p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein If a <code class="option">file</code> is specified, then the zone is
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt read from that file; the largest TTL and the DNSKEY TTL are
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1Mark Andrews determined directly from the zone data, and the
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <code class="option">-m</code> and <code class="option">-d</code> options do
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein not need to be specified on the command line.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p></dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-l <em class="replaceable"><code>duration</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The length of time to check for DNSSEC coverage. Key events
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein scheduled further into the future than <code class="option">duration</code>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein will be ignored, and assumed to be correct.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The value of <code class="option">duration</code> can be set in seconds,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein or in larger units of time by adding a suffix: 'mi' for minutes,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 'h' for hours, 'd' for days, 'w' for weeks, 'mo' for months,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 'y' for years.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-m <em class="replaceable"><code>maximum TTL</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Sets the value to be used as the maximum TTL for the zone or
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein zones being analyzed when determining whether there is a
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein possibility of validation failure. When a zone-signing key is
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein deactivated, there must be enough time for the record in the
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein zone with the longest TTL to have expired from resolver caches
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein before that key can be purged from the DNSKEY RRset. If that
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein condition does not apply, a warning will be generated.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The length of the TTL can be set in seconds, or in larger units
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein of time by adding a suffix: 'mi' for minutes, 'h' for hours,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein This option is mandatory unless the <code class="option">-f</code> has
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein been used to specify a zone file. (If <code class="option">-f</code> has
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein been specified, this option may still be used; it will override
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein the value found in the file.)
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-d <em class="replaceable"><code>DNSKEY TTL</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Sets the value to be used as the DNSKEY TTL for the zone or
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt zones being analyzed when determining whether there is a
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt possibility of validation failure. When a key is rolled (that
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt is, replaced with a new key), there must be enough time
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1Mark Andrews for the old DNSKEY RRset to have expired from resolver caches
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein before the new key is activated and begins generating
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein signatures. If that condition does not apply, a warning
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein will be generated.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The length of the TTL can be set in seconds, or in larger units
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein of time by adding a suffix: 'mi' for minutes, 'h' for hours,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein This option is mandatory unless the <code class="option">-f</code> has
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein been used to specify a zone file, or a default key TTL was
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein set with the <code class="option">-L</code> to
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span><strong class="command">dnssec-keygen</strong></span>. (If either of those is true,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein this option may still be used; it will override the value found
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein in the zone or key file.)
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-r <em class="replaceable"><code>resign interval</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Sets the value to be used as the resign interval for the zone
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein or zones being analyzed when determining whether there is a
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein possibility of validation failure. This value defaults to
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 22.5 days, which is also the default in
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span><strong class="command">named</strong></span>. However, if it has been changed
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein by the <code class="option">sig-validity-interval</code> option in
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <code class="filename">named.conf</code>, then it should also be
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein changed here.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein The length of the interval can be set in seconds, or in larger
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein units of time by adding a suffix: 'mi' for minutes, 'h' for hours,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein 'd' for days, 'w' for weeks, 'mo' for months, 'y' for years.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-k</span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd><p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Only check KSK coverage; ignore ZSK events. Cannot be
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein used with <code class="option">-z</code>.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p></dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-z</span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd><p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Only check ZSK coverage; ignore KSK events. Cannot be
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein used with <code class="option">-k</code>.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p></dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dt><span class="term">-c <em class="replaceable"><code>compilezone path</code></em></span></dt>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<dd><p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Specifies a path to a <span><strong class="command">named-compilezone</strong></span> binary.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein Used for testing.
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p></dd>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</dl></div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</div>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="refsect1" lang="en">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<a name="id2619146"></a><h2>SEE ALSO</h2>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span class="citerefentry"><span class="refentrytitle">dnssec-checkds</span>(8)</span>,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span class="citerefentry"><span class="refentrytitle">dnssec-dsfromkey</span>(8)</span>,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt </p>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt</div>
30eec077db2bdcb6f2a0dc388a3cdde2ede75ec1Mark Andrews<div class="refsect1" lang="en">
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<a name="id2619190"></a><h2>AUTHOR</h2>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein<p><span class="corpauthor">Internet Systems Consortium</span>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein </p>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</div>
268a4475065fe6a8cd7cc707820982cf5e98f430Rob Austein</div>
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<div class="navfooter">
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.dnssec-checkds.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-dsfromkey.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">dnssec-checkds</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">dnssec-dsfromkey</span>
</td>
</tr>
</table>
</div>
<p style="text-align: center;">BIND 9.11.0pre-alpha</p>
</body>
</html>