man.dnssec-dsfromkey.html revision cd791043c8a6edbcacc2392575a9816d19b8157c
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<!--
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - Copyright (C) 2000-2003 Internet Software Consortium.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington -
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - Permission to use, copy, modify, and/or distribute this software for any
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - purpose with or without fee is hereby granted, provided that the above
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - copyright notice and this permission notice appear in all copies.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington -
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington - PERFORMANCE OF THIS SOFTWARE.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington-->
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<!-- $Id$ -->
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<html>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<head>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<title>dnssec-dsfromkey</title>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<link rel="prev" href="man.host.html" title="host">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<link rel="next" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</head>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="navheader">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<table width="100%" summary="Navigation header">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<tr><th colspan="3" align="center"><span class="application">dnssec-dsfromkey</span></th></tr>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<tr>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<td width="20%" align="left">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<a accesskey="p" href="man.host.html">Prev</a>�</td>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<th width="60%" align="center">Manual pages</th>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</td>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</tr>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</table>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<hr>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="refentry" lang="en">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<a name="man.dnssec-dsfromkey"></a><div class="titlepage"></div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="refnamediv">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<h2>Name</h2>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<p><span class="application">dnssec-dsfromkey</span> &#8212; DNSSEC DS RR generation tool</p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="refsynopsisdiv">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<h2>Synopsis</h2>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-1</code>] [<code class="option">-2</code>] [<code class="option">-a <em class="replaceable"><code>alg</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-T <em class="replaceable"><code>TTL</code></em></code>] {keyfile}</p></div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code> {-s} [<code class="option">-1</code>] [<code class="option">-2</code>] [<code class="option">-a <em class="replaceable"><code>alg</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-s</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-T <em class="replaceable"><code>TTL</code></em></code>] [<code class="option">-f <em class="replaceable"><code>file</code></em></code>] [<code class="option">-A</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {dnsname}</p></div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="refsect1" lang="en">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<a name="id2612536"></a><h2>DESCRIPTION</h2>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<p><span><strong class="command">dnssec-dsfromkey</strong></span>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington outputs the Delegation Signer (DS) resource record (RR), as defined in
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington RFC 3658 and RFC 4509, for the given key(s).
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington</div>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="refsect1" lang="en">
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<a name="id2612550"></a><h2>OPTIONS</h2>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<div class="variablelist"><dl>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-1</span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd><p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Use SHA-1 as the digest algorithm (the default is to use
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington both SHA-1 and SHA-256).
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p></dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-2</span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd><p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Use SHA-256 as the digest algorithm.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p></dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd><p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Select the digest algorithm. The value of
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington <code class="option">algorithm</code> must be one of SHA-1 (SHA1),
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington SHA-256 (SHA256), GOST or SHA-384 (SHA384).
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington These values are case insensitive.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p></dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-T <em class="replaceable"><code>TTL</code></em></span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd><p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Specifies the TTL of the DS records.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p></dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd><p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Look for key files (or, in keyset mode,
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington <code class="filename">keyset-</code> files) in
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington <code class="option">directory</code>.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p></dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dt><span class="term">-f <em class="replaceable"><code>file</code></em></span></dt>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<dd>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington Zone file mode: in place of the keyfile name, the argument is
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington the DNS domain name of a zone master file, which can be read
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington from <code class="option">file</code>. If the zone name is the same as
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington <code class="option">file</code>, then it may be omitted.
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington If <code class="option">file</code> is set to <code class="literal">"-"</code>, then
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington the zone data is read from the standard input. This makes it
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington possible to use the output of the <span><strong class="command">dig</strong></span>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington command as input, as in:
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington </p>
9446b3153033ef93a59c5288074e6c688e7fdf5dPhill Cunnington<p>
<strong class="userinput"><code>dig dnskey example.com | dnssec-dsfromkey -f - example.com</code></strong>
</p>
</dd>
<dt><span class="term">-A</span></dt>
<dd><p>
Include ZSK's when generating DS records. Without this option,
only keys which have the KSK flag set will be converted to DS
records and printed. Useful only in zone file mode.
</p></dd>
<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
<dd><p>
Generate a DLV set instead of a DS set. The specified
<code class="option">domain</code> is appended to the name for each
record in the set.
The DNSSEC Lookaside Validation (DLV) RR is described
in RFC 4431.
</p></dd>
<dt><span class="term">-s</span></dt>
<dd><p>
Keyset mode: in place of the keyfile name, the argument is
the DNS domain name of a keyset file.
</p></dd>
<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
<dd><p>
Specifies the DNS class (default is IN). Useful only
in keyset or zone file mode.
</p></dd>
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
<dd><p>
Sets the debugging level.
</p></dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
<a name="id2613945"></a><h2>EXAMPLE</h2>
<p>
To build the SHA-256 DS RR from the
<strong class="userinput"><code>Kexample.com.+003+26160</code></strong>
keyfile name, the following command would be issued:
</p>
<p><strong class="userinput"><code>dnssec-dsfromkey -2 Kexample.com.+003+26160</code></strong>
</p>
<p>
The command would print something like:
</p>
<p><strong class="userinput"><code>example.com. IN DS 26160 5 2 3A1EADA7A74B8D0BA86726B0C227AA85AB8BBD2B2004F41A868A54F0 C5EA0B94</code></strong>
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2613981"></a><h2>FILES</h2>
<p>
The keyfile can be designed by the key identification
<code class="filename">Knnnn.+aaa+iiiii</code> or the full file name
<code class="filename">Knnnn.+aaa+iiiii.key</code> as generated by
<span class="refentrytitle">dnssec-keygen</span>(8).
</p>
<p>
The keyset file name is built from the <code class="option">directory</code>,
the string <code class="filename">keyset-</code> and the
<code class="option">dnsname</code>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2614023"></a><h2>CAVEAT</h2>
<p>
A keyfile error can give a "file not found" even if the file exists.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2614033"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
<span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 3658</em>,
<em class="citetitle">RFC 4431</em>.
<em class="citetitle">RFC 4509</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2614072"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.host.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">host�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">dnssec-keyfromlabel</span>
</td>
</tr>
</table>
</div>
</body>
</html>