man.dnssec-keyfromlabel.html revision 8de0d8a6905e397ed0a26054815420685f9b435e
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - Copyright (C) 2000-2003 Internet Software Consortium.
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - Permission to use, copy, modify, and/or distribute this software for any
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - purpose with or without fee is hereby granted, provided that the above
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync - copyright notice and this permission notice appear in all copies.
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync - PERFORMANCE OF THIS SOFTWARE.
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync<!-- $Id: man.dnssec-keyfromlabel.html,v 1.68 2009/10/11 01:14:48 tbox Exp $ -->
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<link rel="prev" href="man.dnssec-dsfromkey.html" title="dnssec-dsfromkey">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<link rel="next" href="man.dnssec-keygen.html" title="dnssec-keygen">
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync<tr><th colspan="3" align="center"><span class="application">dnssec-keyfromlabel</span></th></tr>
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync<a accesskey="p" href="man.dnssec-dsfromkey.html">Prev</a>�</td>
01ea175f55740168d1dd0af3277d3b86a30b4f91vboxsync<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-keygen.html">Next</a>
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync<a name="man.dnssec-keyfromlabel"></a><div class="titlepage"></div>
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync<p><span class="application">dnssec-keyfromlabel</span> — DNSSEC key generation tool</p>
9040f019271f91b98e1320c0a8c38a42636e3979vboxsync<div class="cmdsynopsis"><p><code class="command">dnssec-keyfromlabel</code> {-l <em class="replaceable"><code>label</code></em>} [<code class="option">-3</code>] [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-k</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] {name}</p></div>
1b959a8e2774712c95bd7628282e9e41f0c5f03evboxsync<p><span><strong class="command">dnssec-keyfromlabel</strong></span>
1b959a8e2774712c95bd7628282e9e41f0c5f03evboxsync gets keys with the given label from a crypto hardware and builds
6a008ce8150c1391d9e0dda0cdf9485b3c806034vboxsync key files for DNSSEC (Secure DNS), as defined in RFC 2535
6a008ce8150c1391d9e0dda0cdf9485b3c806034vboxsync and RFC 4034.
6a008ce8150c1391d9e0dda0cdf9485b3c806034vboxsync The <code class="option">name</code> of the key is specified on the command
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync line. This must match the name of the zone for which the key is
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync being generated.
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
f6bee36bd88580a116ce05e7c58e7799c599a782vboxsync Selects the cryptographic algorithm. The value of
f6bee36bd88580a116ce05e7c58e7799c599a782vboxsync <code class="option">algorithm</code> must be one of RSAMD5 (RSA),
f6bee36bd88580a116ce05e7c58e7799c599a782vboxsync RSASHA1, DSA, NSEC3RSASHA1, NSEC3DSA or DH (Diffie Hellman).
f6bee36bd88580a116ce05e7c58e7799c599a782vboxsync These values are case insensitive.
6a008ce8150c1391d9e0dda0cdf9485b3c806034vboxsync If no algorithm is specified, then RSASHA1 will be used by
6a008ce8150c1391d9e0dda0cdf9485b3c806034vboxsync default, unless the <code class="option">-3</code> option is specified,
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync in which case NSEC3RSASHA1 will be used instead.
f6bee36bd88580a116ce05e7c58e7799c599a782vboxsync Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync algorithm, and DSA is recommended.
edd67c61375d89ff863e754caff339cd1ac77b38vboxsync Note 2: DH automatically sets the -k flag.
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync Use an NSEC3-capable algorithm to generate a DNSSEC key.
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync If this option is used and no algorithm is explicitly
c285785ffc9f35513e0c6e7e2a05df3090dc919cvboxsync set on the command line, NSEC3RSASHA1 will be used by
715e49c31b15c23c17a9ce3be42a75e7c48d4b78vboxsync<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
715e49c31b15c23c17a9ce3be42a75e7c48d4b78vboxsync Specifies the name of the crypto hardware (OpenSSL engine).
339a5a0150dcebd28f8aab6f2e3c293d95405ca9vboxsync When compiled with PKCS#11 support it defaults to "pcks11".
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync<dt><span class="term">-l <em class="replaceable"><code>label</code></em></span></dt>
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync Specifies the label of the key pair in the crypto hardware.
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync The label may be preceded by an optional OpenSSL engine name,
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync separated by a colon, as in "pkcs11:keylabel".
339a5a0150dcebd28f8aab6f2e3c293d95405ca9vboxsync<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync Specifies the owner type of the key. The value of
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync <code class="option">nametype</code> must either be ZONE (for a DNSSEC
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync a host (KEY)),
fe0826de96da565f5a285504b2210f269b8a2de9vboxsync USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
7eaaa8a4480370b82ef3735994f986f338fb4df2vboxsync These values are case insensitive.