man.dnssec-coverage.html revision 90d087cf9c73028362c63eaa41c87acc76fb8ec3
fa9e4066f08beec538e775443c5be79dd423fcabahrens - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
fa9e4066f08beec538e775443c5be79dd423fcabahrens - Copyright (C) 2000-2003 Internet Software Consortium.
17f17c2df4ca603e787c5fc03b7af83519edfd2cbonwick - Permission to use, copy, modify, and/or distribute this software for any
17f17c2df4ca603e787c5fc03b7af83519edfd2cbonwick - purpose with or without fee is hereby granted, provided that the above
fa9e4066f08beec538e775443c5be79dd423fcabahrens - copyright notice and this permission notice appear in all copies.
fa9e4066f08beec538e775443c5be79dd423fcabahrens - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
fa9e4066f08beec538e775443c5be79dd423fcabahrens - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
fa9e4066f08beec538e775443c5be79dd423fcabahrens - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
fa9e4066f08beec538e775443c5be79dd423fcabahrens - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
fa9e4066f08beec538e775443c5be79dd423fcabahrens - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
fa9e4066f08beec538e775443c5be79dd423fcabahrens - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
fa9e4066f08beec538e775443c5be79dd423fcabahrens - PERFORMANCE OF THIS SOFTWARE.
fa9e4066f08beec538e775443c5be79dd423fcabahrens<!-- $Id$ -->
fa9e4066f08beec538e775443c5be79dd423fcabahrens<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
b24ab6762772a3f6a89393947930c7fa61306783Jeff Bonwick<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
fa9e4066f08beec538e775443c5be79dd423fcabahrens<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
fa9e4066f08beec538e775443c5be79dd423fcabahrens<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens<link rel="prev" href="man.dnssec-checkds.html" title="dnssec-checkds">
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens<link rel="next" href="man.dnssec-dsfromkey.html" title="dnssec-dsfromkey">
fa9e4066f08beec538e775443c5be79dd423fcabahrens<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
97322426b5359bb3ffd4527e1ad8b2c5f7dab832Darren J Moffat<table width="100%" summary="Navigation header">
fa9e4066f08beec538e775443c5be79dd423fcabahrens<tr><th colspan="3" align="center"><span class="application">dnssec-coverage</span></th></tr>
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens<a accesskey="p" href="man.dnssec-checkds.html">Prev</a>�</td>
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens<th width="60%" align="center">Manual pages</th>
fa9e4066f08beec538e775443c5be79dd423fcabahrens<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-dsfromkey.html">Next</a>
97322426b5359bb3ffd4527e1ad8b2c5f7dab832Darren J Moffat<a name="man.dnssec-coverage"></a><div class="titlepage"></div>
97322426b5359bb3ffd4527e1ad8b2c5f7dab832Darren J Moffat<p><span class="application">dnssec-coverage</span> — checks future DNSKEY coverage for a zone</p>
97322426b5359bb3ffd4527e1ad8b2c5f7dab832Darren J Moffat<div class="cmdsynopsis"><p><code class="command">dnssec-coverage</code> [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-l <em class="replaceable"><code>length</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-d <em class="replaceable"><code>DNSKEY TTL</code></em></code>] [<code class="option">-m <em class="replaceable"><code>max TTL</code></em></code>] [<code class="option">-r <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-c <em class="replaceable"><code>compilezone path</code></em></code>] [<code class="option">-k</code>] [<code class="option">-z</code>] [zone]</p></div>
97322426b5359bb3ffd4527e1ad8b2c5f7dab832Darren J Moffat<p><span><strong class="command">dnssec-coverage</strong></span>
fa9e4066f08beec538e775443c5be79dd423fcabahrens verifies that the DNSSEC keys for a given zone or a set of zones
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens have timing metadata set properly to ensure no future lapses in DNSSEC
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens If <code class="option">zone</code> is specified, then keys found in
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens the key repository matching that zone are scanned, and an ordered
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens list is generated of the events scheduled for that key (i.e.,
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens publication, activation, inactivation, deletion). The list of
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens events is walked in order of occurrence. Warnings are generated
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens if any event is scheduled which could cause the zone to enter a
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens state in which validation failures might occur: for example, if
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens the number of published or active keys for a given algorithm drops
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens to zero, or if a key is deleted from the zone too soon after a new
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens key is rolled, and cached data signed by the prior key has not had
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens time to expire from resolver caches.
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens If <code class="option">zone</code> is not specified, then all keys in the
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens key repository will be scanned, and all zones for which there are
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens keys will be analyzed. (Note: This method of reporting is only
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens accurate if all the zones that have keys in a given repository
45818ee124adeaaf947698996b4f4c722afc6d1fMatthew Ahrens share the same TTL parameters.)