man.dnssec-keyfromlabel.html revision e4adb07cc1f8253b3c39aeeeb3ea03dc5b7011cc
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - Copyright (C) 2000-2003 Internet Software Consortium.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - Permission to use, copy, modify, and/or distribute this software for any
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - purpose with or without fee is hereby granted, provided that the above
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - copyright notice and this permission notice appear in all copies.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync - PERFORMANCE OF THIS SOFTWARE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<!-- $Id: man.dnssec-keyfromlabel.html,v 1.74 2009/10/27 01:14:44 tbox Exp $ -->
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<link rel="prev" href="man.dnssec-dsfromkey.html" title="dnssec-dsfromkey">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<link rel="next" href="man.dnssec-keygen.html" title="dnssec-keygen">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<tr><th colspan="3" align="center"><span class="application">dnssec-keyfromlabel</span></th></tr>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<a accesskey="p" href="man.dnssec-dsfromkey.html">Prev</a>�</td>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-keygen.html">Next</a>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<a name="man.dnssec-keyfromlabel"></a><div class="titlepage"></div>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<p><span class="application">dnssec-keyfromlabel</span> — DNSSEC key generation tool</p>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {name}</p></div>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync gets keys with the given label from a crypto hardware and builds
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync key files for DNSSEC (Secure DNS), as defined in RFC 2535
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync and RFC 4034.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The <code class="option">name</code> of the key is specified on the command
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync line. This must match the name of the zone for which the key is
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync being generated.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Selects the cryptographic algorithm. The value of
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256 or RSASHA512.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync These values are case insensitive.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If no algorithm is specified, then RSASHA1 will be used by
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync default, unless the <code class="option">-3</code> option is specified,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync in which case NSEC3RSASHA1 will be used instead. (If
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <code class="option">-3</code> is used and an algorithm is specified,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync that algorithm will be checked for compatibility with NSEC3.)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync algorithm, and DSA is recommended.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Note 2: DH automatically sets the -k flag.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Use an NSEC3-capable algorithm to generate a DNSSEC key.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If this option is used and no algorithm is explicitly
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync set on the command line, NSEC3RSASHA1 will be used by
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Specifies the name of the crypto hardware (OpenSSL engine).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync When compiled with PKCS#11 support it defaults to "pcks11".
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-l <em class="replaceable"><code>label</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Specifies the label of the key pair in the crypto hardware.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The label may be preceded by an optional OpenSSL engine name,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync separated by a colon, as in "pkcs11:keylabel".
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Specifies the owner type of the key. The value of
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <code class="option">nametype</code> must either be ZONE (for a DNSSEC
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync a host (KEY)),
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync These values are case insensitive.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Compatibility mode: generates an old-style key, without
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync any metadata. By default, <span><strong class="command">dnssec-keyfromlabel</strong></span>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync will include the key's creation date in the metadata stored
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync with the private key, and other dates may be set there as well
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync (publication date, activation date, etc). Keys that include
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync this data may be incompatible with older versions of BIND; the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <code class="option">-C</code> option suppresses them.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Indicates that the DNS record containing the key should have
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync the specified class. If not specified, class IN is used.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Set the specified flag in the flag field of the KEY/DNSKEY record.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The only recognized flags are KSK (Key Signing Key) and REVOKE.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Generate a key, but do not publish it or sign with it. This
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync option is incompatible with -P and -A.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Prints a short summary of the options and arguments to
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <span><strong class="command">dnssec-keyfromlabel</strong></span>.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the directory in which the key files are to be written.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Generate KEY records rather than DNSKEY records.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the protocol value for the key. The protocol
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync is a number between 0 and 255. The default is 3 (DNSSEC).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Other possible values for this argument are listed in
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync RFC 2535 and its successors.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Indicates the use of the key. <code class="option">type</code> must be
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync is AUTHCONF. AUTH refers to the ability to authenticate
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync data, and CONF the ability to encrypt data.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the debugging level.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync If the argument begins with a '+' or '-', it is interpreted as
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync an offset from the present time. For convenience, if such an offset
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync then the offset is computed in years (defined as 365 24-hour days,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync ignoring leap years), months (defined as 30 24-hour days), weeks,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync days, hours, or minutes, respectively. Without a suffix, the offset
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync is computed in seconds.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the date on which a key is to be published to the zone.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync After that date, the key will be included in the zone but will
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync not be used to sign it. If not set, and if the -G option has
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync not been used, the default is "now".
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the date on which the key is to be activated. After that
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync date, the key will be included in the zone and used to sign
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync it. If not set, and if the -G option has not been used, the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync default is "now".
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the date on which the key is to be revoked. After that
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync date, the key will be flagged as revoked. It will be included
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync in the zone and will be used to sign it.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-U <em class="replaceable"><code>date/offset</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the date on which the key is to be retired. After that
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync date, the key will still be included in the zone, but it
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync will not be used to sign it.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync Sets the date on which the key is to be deleted. After that
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync date, the key will no longer be included in the zone. (It
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync may remain in the key repository, however.)
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<a name="id2609856"></a><h2>GENERATED KEY FILES</h2>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync When <span><strong class="command">dnssec-keyfromlabel</strong></span> completes
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync successfully,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync it prints a string of the form <code class="filename">Knnnn.+aaa+iiiii</code>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync to the standard output. This is an identification string for
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync the key files it has generated.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<li><p><code class="filename">nnnn</code> is the key name.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<li><p><code class="filename">aaa</code> is the numeric representation
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync of the algorithm.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<li><p><code class="filename">iiiii</code> is the key identifier (or
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync footprint).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync creates two files, with names based
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync contains the public key, and
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <code class="filename">Knnnn.+aaa+iiiii.private</code> contains the
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync private key.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The <code class="filename">.key</code> file contains a DNS KEY record
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync can be inserted into a zone file (directly or with a $INCLUDE
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync statement).
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync The <code class="filename">.private</code> file contains
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync algorithm-specific
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync fields. For obvious security reasons, this file does not have
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync general read permission.
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<p><span class="corpauthor">Internet Systems Consortium</span>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<a accesskey="p" href="man.dnssec-dsfromkey.html">Prev</a>�</td>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-keygen.html">Next</a>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<span class="application">dnssec-dsfromkey</span>�</td>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
4fd606d1f5abe38e1f42c38de1d2e895166bd0f4vboxsync<td width="40%" align="right" valign="top">�<span class="application">dnssec-keygen</span>