man.dnssec-importkey.html revision c60ee6edf129596fa04db86c6865d75b5a412598
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<!--
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - purpose with or without fee is hereby granted, provided that the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - copyright notice and this permission notice appear in all copies.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster -
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - PERFORMANCE OF THIS SOFTWARE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster-->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- $Id$ -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<html>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<head>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<title>dnssec-importkey</title>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="prev" href="man.dnssec-dsfromkey.html" title="dnssec-dsfromkey">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="next" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington</head>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="navheader">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation header">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr><th colspan="3" align="center"><span class="application">dnssec-importkey</span></th></tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="left">
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<a accesskey="p" href="man.dnssec-dsfromkey.html">Prev</a>�</td>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<th width="60%" align="center">Manual pages</th>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</table>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<hr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refentry" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="man.dnssec-importkey"></a><div class="titlepage"></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refnamediv">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h2>Name</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="application">dnssec-importkey</span> &#8212; Import DNSKEY records from external systems so they can be managed.</p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsynopsisdiv">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<h2>Synopsis</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="cmdsynopsis"><p><code class="command">dnssec-importkey</code> [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] {<code class="option">keyfile</code>}</p></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="cmdsynopsis"><p><code class="command">dnssec-importkey</code> {<code class="option">-f <em class="replaceable"><code>filename</code></em></code>} [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">dnsname</code>]</p></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2621399"></a><h2>DESCRIPTION</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span><strong class="command">dnssec-importkey</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster reads a public DNSKEY record and generates a pair of
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster .key/.private files. The DNSKEY record may be read from an
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster existing .key file, in which case a corresponding .private file
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington will be generated, or it may be read from any other file or
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster from the standard input, in which case both .key and .private
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster files will be generated.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The newly-created .private file does <span class="emphasis"><em>not</em></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster contain private key data, and cannot be used for signing.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster However, having a .private file makes it possible to set
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster publication (<code class="option">-P</code>) and deletion
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (<code class="option">-D</code>) times for the key, which means the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster public key can be added to and removed from the DNSKEY RRset
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster on schedule even if the true private key is stored offline.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2621427"></a><h2>OPTIONS</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="variablelist"><dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-f <em class="replaceable"><code>filename</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Zone file mode: instead of a public keyfile name, the argument
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster is the DNS domain name of a zone master file, which can be read
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster from <code class="option">file</code>. If the domain name is the same as
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">file</code>, then it may be omitted.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If <code class="option">file</code> is set to <code class="literal">"-"</code>, then
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the zone data is read from the standard input.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the directory in which the key files are to reside.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the default TTL to use for this key when it is converted
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster into a DNSKEY RR. If the key is imported into a zone,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster this is the TTL that will be used for it, unless there was
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster already a DNSKEY RRset in place, in which case the existing TTL
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster would take precedence. Setting the default TTL to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="literal">0</code> or <code class="literal">none</code> removes it.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-h</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Emit usage message and exit.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the debugging level.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-V</span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Prints version information.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2621564"></a><h2>TIMING OPTIONS</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If the argument begins with a '+' or '-', it is interpreted as
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster an offset from the present time. For convenience, if such an offset
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster then the offset is computed in years (defined as 365 24-hour days,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ignoring leap years), months (defined as 30 24-hour days), weeks,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster days, hours, or minutes, respectively. Without a suffix, the offset
bee2440354b4bc8796e1de0b6cbd60e1f68deba0Phill Cunnington is computed in seconds. To explicitly prevent a date from being
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster set, use 'none' or 'never'.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="variablelist"><dl>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the date on which a key is to be published to the zone.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster After that date, the key will be included in the zone but will
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster not be used to sign it.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dd><p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the date on which the key is to be deleted. After that
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster date, the key will no longer be included in the zone. (It
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster may remain in the key repository, however.)
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p></dd>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</dl></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2621680"></a><h2>FILES</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster A keyfile can be designed by the key identification
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">Knnnn.+aaa+iiiii</code> or the full file name
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="filename">Knnnn.+aaa+iiiii.key</code> as generated by
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="refentrytitle">dnssec-keygen</span>(8).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster </p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster</div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="refsect1" lang="en">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="id2621705"></a><h2>SEE ALSO</h2>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <em class="citetitle">RFC 5011</em>.
</p>
</div>
<div class="refsect1" lang="en">
<a name="id2621806"></a><h2>AUTHOR</h2>
<p><span class="corpauthor">Internet Systems Consortium</span>
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.dnssec-dsfromkey.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">dnssec-dsfromkey</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">dnssec-keyfromlabel</span>
</td>
</tr>
</table>
</div>
<p style="text-align: center;">BIND 9.11.0pre-alpha</p>
</body>
</html>