man.dnssec-keyfromlabel.html revision 3e240d6559605696cadf630668683708b18de871
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - Copyright (C) 2000-2003 Internet Software Consortium.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - Permission to use, copy, modify, and/or distribute this software for any
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - purpose with or without fee is hereby granted, provided that the above
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - copyright notice and this permission notice appear in all copies.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
25cf1a301a396c38e8adf52c15f537b80d2483f7jl - PERFORMANCE OF THIS SOFTWARE.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<!-- $Id$ -->
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<link rel="prev" href="man.dnssec-importkey.html" title="dnssec-importkey">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<link rel="next" href="man.dnssec-keygen.html" title="dnssec-keygen">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<tr><th colspan="3" align="center"><span class="application">dnssec-keyfromlabel</span></th></tr>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<a accesskey="p" href="man.dnssec-importkey.html">Prev</a>�</td>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-keygen.html">Next</a>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<a name="man.dnssec-keyfromlabel"></a><div class="titlepage"></div>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<p><span class="application">dnssec-keyfromlabel</span> — DNSSEC key generation tool</p>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-y</code>] {name}</p></div>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl generates a key pair of files that referencing a key object stored
25cf1a301a396c38e8adf52c15f537b80d2483f7jl in a cryptographic hardware service module (HSM). The private key
25cf1a301a396c38e8adf52c15f537b80d2483f7jl file can be used for DNSSEC signing of zone data as if it were a
25cf1a301a396c38e8adf52c15f537b80d2483f7jl conventional signing key created by <span><strong class="command">dnssec-keygen</strong></span>,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl but the key material is stored within the HSM, and the actual signing
25cf1a301a396c38e8adf52c15f537b80d2483f7jl takes place there.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl The <code class="option">name</code> of the key is specified on the command
25cf1a301a396c38e8adf52c15f537b80d2483f7jl line. This must match the name of the zone for which the key is
25cf1a301a396c38e8adf52c15f537b80d2483f7jl being generated.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Selects the cryptographic algorithm. The value of
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl ECDSAP256SHA256 or ECDSAP384SHA384.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl These values are case insensitive.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl If no algorithm is specified, then RSASHA1 will be used by
25cf1a301a396c38e8adf52c15f537b80d2483f7jl default, unless the <code class="option">-3</code> option is specified,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl in which case NSEC3RSASHA1 will be used instead. (If
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="option">-3</code> is used and an algorithm is specified,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl that algorithm will be checked for compatibility with NSEC3.)
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
25cf1a301a396c38e8adf52c15f537b80d2483f7jl algorithm, and DSA is recommended.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Note 2: DH automatically sets the -k flag.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Use an NSEC3-capable algorithm to generate a DNSSEC key.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl If this option is used and no algorithm is explicitly
25cf1a301a396c38e8adf52c15f537b80d2483f7jl set on the command line, NSEC3RSASHA1 will be used by
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Specifies the cryptographic hardware to use.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl When BIND is built with OpenSSL PKCS#11 support, this defaults
25cf1a301a396c38e8adf52c15f537b80d2483f7jl to the string "pkcs11", which identifies an OpenSSL engine
25cf1a301a396c38e8adf52c15f537b80d2483f7jl that can drive a cryptographic accelerator or hardware service
25cf1a301a396c38e8adf52c15f537b80d2483f7jl module. When BIND is built with native PKCS#11 cryptography
25cf1a301a396c38e8adf52c15f537b80d2483f7jl (--enable-native-pkcs11), it defaults to the path of the PKCS#11
25cf1a301a396c38e8adf52c15f537b80d2483f7jl provider library specified via "--with-pkcs11".
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-l <em class="replaceable"><code>label</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Specifies the label for a key pair in the crypto hardware.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl When <acronym class="acronym">BIND</acronym> 9 is built with OpenSSL-based
25cf1a301a396c38e8adf52c15f537b80d2483f7jl PKCS#11 support, the label is an arbitrary string that
25cf1a301a396c38e8adf52c15f537b80d2483f7jl identifies a particular key. It may be preceded by an
25cf1a301a396c38e8adf52c15f537b80d2483f7jl optional OpenSSL engine name, followed by a colon, as in
25cf1a301a396c38e8adf52c15f537b80d2483f7jl "pkcs11:<em class="replaceable"><code>keylabel</code></em>".
25cf1a301a396c38e8adf52c15f537b80d2483f7jl When <acronym class="acronym">BIND</acronym> 9 is built with native PKCS#11
25cf1a301a396c38e8adf52c15f537b80d2483f7jl support, the label is a PKCS#11 URI string in the format
25cf1a301a396c38e8adf52c15f537b80d2483f7jl "pkcs11:<code class="option">keyword</code>=<em class="replaceable"><code>value</code></em>[<span class="optional">;<code class="option">keyword</code>=<em class="replaceable"><code>value</code></em>;...</span>]"
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Keywords include "token", which identifies the HSM; "object", which
25cf1a301a396c38e8adf52c15f537b80d2483f7jl identifies the key; and "pin-source", which identifies a file from
25cf1a301a396c38e8adf52c15f537b80d2483f7jl which the HSM's PIN code can be obtained. The label will be
25cf1a301a396c38e8adf52c15f537b80d2483f7jl stored in the on-disk "private" file.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl If the label contains a
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="option">pin-source</code> field, tools using the generated
25cf1a301a396c38e8adf52c15f537b80d2483f7jl key files will be able to use the HSM for signing and other
25cf1a301a396c38e8adf52c15f537b80d2483f7jl operations without any need for an operator to manually enter
25cf1a301a396c38e8adf52c15f537b80d2483f7jl a PIN. Note: Making the HSM's PIN accessible in this manner
25cf1a301a396c38e8adf52c15f537b80d2483f7jl may reduce the security advantage of using an HSM; be sure
25cf1a301a396c38e8adf52c15f537b80d2483f7jl this is what you want to do before making use of this feature.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Specifies the owner type of the key. The value of
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="option">nametype</code> must either be ZONE (for a DNSSEC
25cf1a301a396c38e8adf52c15f537b80d2483f7jl zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
25cf1a301a396c38e8adf52c15f537b80d2483f7jl a host (KEY)),
25cf1a301a396c38e8adf52c15f537b80d2483f7jl USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
25cf1a301a396c38e8adf52c15f537b80d2483f7jl These values are case insensitive.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Compatibility mode: generates an old-style key, without
25cf1a301a396c38e8adf52c15f537b80d2483f7jl any metadata. By default, <span><strong class="command">dnssec-keyfromlabel</strong></span>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl will include the key's creation date in the metadata stored
25cf1a301a396c38e8adf52c15f537b80d2483f7jl with the private key, and other dates may be set there as well
25cf1a301a396c38e8adf52c15f537b80d2483f7jl (publication date, activation date, etc). Keys that include
25cf1a301a396c38e8adf52c15f537b80d2483f7jl this data may be incompatible with older versions of BIND; the
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Indicates that the DNS record containing the key should have
25cf1a301a396c38e8adf52c15f537b80d2483f7jl the specified class. If not specified, class IN is used.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Set the specified flag in the flag field of the KEY/DNSKEY record.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl The only recognized flags are KSK (Key Signing Key) and REVOKE.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Generate a key, but do not publish it or sign with it. This
25cf1a301a396c38e8adf52c15f537b80d2483f7jl option is incompatible with -P and -A.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Prints a short summary of the options and arguments to
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <span><strong class="command">dnssec-keyfromlabel</strong></span>.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the directory in which the key files are to be written.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Generate KEY records rather than DNSKEY records.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the default TTL to use for this key when it is converted
25cf1a301a396c38e8adf52c15f537b80d2483f7jl into a DNSKEY RR. If the key is imported into a zone,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl this is the TTL that will be used for it, unless there was
25cf1a301a396c38e8adf52c15f537b80d2483f7jl already a DNSKEY RRset in place, in which case the existing TTL
25cf1a301a396c38e8adf52c15f537b80d2483f7jl would take precedence. Setting the default TTL to
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="literal">0</code> or <code class="literal">none</code> removes it.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the protocol value for the key. The protocol
25cf1a301a396c38e8adf52c15f537b80d2483f7jl is a number between 0 and 255. The default is 3 (DNSSEC).
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Other possible values for this argument are listed in
25cf1a301a396c38e8adf52c15f537b80d2483f7jl RFC 2535 and its successors.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Generate a key as an explicit successor to an existing key.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl The name, algorithm, size, and type of the key will be set
25cf1a301a396c38e8adf52c15f537b80d2483f7jl to match the predecessor. The activation date of the new
25cf1a301a396c38e8adf52c15f537b80d2483f7jl key will be set to the inactivation date of the existing
25cf1a301a396c38e8adf52c15f537b80d2483f7jl one. The publication date will be set to the activation
25cf1a301a396c38e8adf52c15f537b80d2483f7jl date minus the prepublication interval, which defaults to
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Indicates the use of the key. <code class="option">type</code> must be
25cf1a301a396c38e8adf52c15f537b80d2483f7jl one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
25cf1a301a396c38e8adf52c15f537b80d2483f7jl is AUTHCONF. AUTH refers to the ability to authenticate
25cf1a301a396c38e8adf52c15f537b80d2483f7jl data, and CONF the ability to encrypt data.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the debugging level.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Prints version information.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Allows DNSSEC key files to be generated even if the key ID
25cf1a301a396c38e8adf52c15f537b80d2483f7jl would collide with that of an existing key, in the event of
25cf1a301a396c38e8adf52c15f537b80d2483f7jl either key being revoked. (This is only safe to use if you
25cf1a301a396c38e8adf52c15f537b80d2483f7jl are sure you won't be using RFC 5011 trust anchor maintenance
25cf1a301a396c38e8adf52c15f537b80d2483f7jl with either of the keys involved.)
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl If the argument begins with a '+' or '-', it is interpreted as
25cf1a301a396c38e8adf52c15f537b80d2483f7jl an offset from the present time. For convenience, if such an offset
25cf1a301a396c38e8adf52c15f537b80d2483f7jl is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
25cf1a301a396c38e8adf52c15f537b80d2483f7jl then the offset is computed in years (defined as 365 24-hour days,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl ignoring leap years), months (defined as 30 24-hour days), weeks,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl days, hours, or minutes, respectively. Without a suffix, the offset
25cf1a301a396c38e8adf52c15f537b80d2483f7jl is computed in seconds. To explicitly prevent a date from being
25cf1a301a396c38e8adf52c15f537b80d2483f7jl set, use 'none' or 'never'.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the date on which a key is to be published to the zone.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl After that date, the key will be included in the zone but will
25cf1a301a396c38e8adf52c15f537b80d2483f7jl not be used to sign it. If not set, and if the -G option has
25cf1a301a396c38e8adf52c15f537b80d2483f7jl not been used, the default is "now".
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the date on which the key is to be activated. After that
25cf1a301a396c38e8adf52c15f537b80d2483f7jl date, the key will be included in the zone and used to sign
25cf1a301a396c38e8adf52c15f537b80d2483f7jl it. If not set, and if the -G option has not been used, the
25cf1a301a396c38e8adf52c15f537b80d2483f7jl default is "now".
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the date on which the key is to be revoked. After that
25cf1a301a396c38e8adf52c15f537b80d2483f7jl date, the key will be flagged as revoked. It will be included
25cf1a301a396c38e8adf52c15f537b80d2483f7jl in the zone and will be used to sign it.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the date on which the key is to be retired. After that
25cf1a301a396c38e8adf52c15f537b80d2483f7jl date, the key will still be included in the zone, but it
25cf1a301a396c38e8adf52c15f537b80d2483f7jl will not be used to sign it.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the date on which the key is to be deleted. After that
25cf1a301a396c38e8adf52c15f537b80d2483f7jl date, the key will no longer be included in the zone. (It
25cf1a301a396c38e8adf52c15f537b80d2483f7jl may remain in the key repository, however.)
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl Sets the prepublication interval for a key. If set, then
25cf1a301a396c38e8adf52c15f537b80d2483f7jl the publication and activation dates must be separated by at least
25cf1a301a396c38e8adf52c15f537b80d2483f7jl this much time. If the activation date is specified but the
25cf1a301a396c38e8adf52c15f537b80d2483f7jl publication date isn't, then the publication date will default
25cf1a301a396c38e8adf52c15f537b80d2483f7jl to this much time before the activation date; conversely, if
25cf1a301a396c38e8adf52c15f537b80d2483f7jl the publication date is specified but activation date isn't,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl then activation will be set to this much time after publication.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl If the key is being created as an explicit successor to another
25cf1a301a396c38e8adf52c15f537b80d2483f7jl key, then the default prepublication interval is 30 days;
25cf1a301a396c38e8adf52c15f537b80d2483f7jl otherwise it is zero.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl As with date offsets, if the argument is followed by one of
25cf1a301a396c38e8adf52c15f537b80d2483f7jl the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
25cf1a301a396c38e8adf52c15f537b80d2483f7jl interval is measured in years, months, weeks, days, hours,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl or minutes, respectively. Without a suffix, the interval is
25cf1a301a396c38e8adf52c15f537b80d2483f7jl measured in seconds.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl When <span><strong class="command">dnssec-keyfromlabel</strong></span> completes
25cf1a301a396c38e8adf52c15f537b80d2483f7jl successfully,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl it prints a string of the form <code class="filename">Knnnn.+aaa+iiiii</code>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl to the standard output. This is an identification string for
25cf1a301a396c38e8adf52c15f537b80d2483f7jl the key files it has generated.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<li><p><code class="filename">nnnn</code> is the key name.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<li><p><code class="filename">aaa</code> is the numeric representation
25cf1a301a396c38e8adf52c15f537b80d2483f7jl of the algorithm.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<li><p><code class="filename">iiiii</code> is the key identifier (or
25cf1a301a396c38e8adf52c15f537b80d2483f7jl footprint).
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl creates two files, with names based
25cf1a301a396c38e8adf52c15f537b80d2483f7jl on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl contains the public key, and
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <code class="filename">Knnnn.+aaa+iiiii.private</code> contains the
25cf1a301a396c38e8adf52c15f537b80d2483f7jl private key.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl The <code class="filename">.key</code> file contains a DNS KEY record
25cf1a301a396c38e8adf52c15f537b80d2483f7jl can be inserted into a zone file (directly or with a $INCLUDE
25cf1a301a396c38e8adf52c15f537b80d2483f7jl statement).
25cf1a301a396c38e8adf52c15f537b80d2483f7jl algorithm-specific
25cf1a301a396c38e8adf52c15f537b80d2483f7jl fields. For obvious security reasons, this file does not have
25cf1a301a396c38e8adf52c15f537b80d2483f7jl general read permission.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
25cf1a301a396c38e8adf52c15f537b80d2483f7jl <em class="citetitle">The PKCS#11 URI Scheme (draft-pechanec-pkcs11uri-13)</em>.
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<p><span class="corpauthor">Internet Systems Consortium</span>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<a accesskey="p" href="man.dnssec-importkey.html">Prev</a>�</td>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-keygen.html">Next</a>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
25cf1a301a396c38e8adf52c15f537b80d2483f7jl<td width="40%" align="right" valign="top">�<span class="application">dnssec-keygen</span>