man.dnssec-keygen.html revision c2258eedf2d9d0207b45b90014f8fde5413b41a3
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<!--
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence - Copyright (C) 2000-2015 Internet Systems Consortium, Inc. ("ISC")
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence -
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence - This Source Code Form is subject to the terms of the Mozilla Public
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence - License, v. 2.0. If a copy of the MPL was not distributed with this
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence - file, You can obtain one at http://mozilla.org/MPL/2.0/.
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence-->
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<html>
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<head>
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<title>dnssec-keygen</title>
dccd7f8459d811141fde04d4a307b9b695cf58b1David Lawrence<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
03f91269f5453bcbd924910ef85a8f8496cf2661Mark Andrews<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
03f91269f5453bcbd924910ef85a8f8496cf2661Mark Andrews<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
03f91269f5453bcbd924910ef85a8f8496cf2661Mark Andrews<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
03f91269f5453bcbd924910ef85a8f8496cf2661Mark Andrews<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
afb0a628efd8ecf40f66f6b8d0711bca62be2a9aMark Andrews</head>
afb0a628efd8ecf40f66f6b8d0711bca62be2a9aMark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
17dba29ba5db791976e505114baee53a1dde88aaBrian Wellington<div class="navheader">
17dba29ba5db791976e505114baee53a1dde88aaBrian Wellington<table width="100%" summary="Navigation header">
17dba29ba5db791976e505114baee53a1dde88aaBrian Wellington<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
17dba29ba5db791976e505114baee53a1dde88aaBrian Wellington<tr>
b5a86fe434c7d58d28af3b5c70c1743979f13aaeMark Andrews<td width="20%" align="left">
b5a86fe434c7d58d28af3b5c70c1743979f13aaeMark Andrews<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
b5a86fe434c7d58d28af3b5c70c1743979f13aaeMark Andrews<th width="60%" align="center">Manual pages</th>
fb13bc029f62193a07d92384a910a0317fc7e0b0Brian Wellington<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
3042b3e2711d00b7fd9ffbf51443ad761d30427fMark Andrews</td>
3042b3e2711d00b7fd9ffbf51443ad761d30427fMark Andrews</tr>
fb13bc029f62193a07d92384a910a0317fc7e0b0Brian Wellington</table>
fb13bc029f62193a07d92384a910a0317fc7e0b0Brian Wellington<hr>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence</div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="refentry">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="refnamediv">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<h2>Name</h2>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<p><span class="application">dnssec-keygen</span> &#8212; DNSSEC key generation tool</p>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence</div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="refsynopsisdiv">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<h2>Synopsis</h2>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-V</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence</div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="refsection">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<a name="id-1.14.11.7"></a><h2>DESCRIPTION</h2>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<p><span class="command"><strong>dnssec-keygen</strong></span>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence and RFC 4034. It can also generate keys for use with
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence (Transaction Key) as defined in RFC 2930.
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence </p>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<p>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence The <code class="option">name</code> of the key is specified on the command
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence line. For DNSSEC keys, this must match the name of the zone for
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence which the key is being generated.
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence </p>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence</div>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="refsection">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<a name="id-1.14.11.8"></a><h2>OPTIONS</h2>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<div class="variablelist"><dl class="variablelist">
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<dd>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence<p>
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence Selects the cryptographic algorithm. For DNSSEC keys, the value
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence ECDSAP256SHA256 or ECDSAP384SHA384.
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence For TSIG/TKEY, the value must
adcd8c93196ad0a3516252d80597c3c52472ffb2David Lawrence be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
5455f30a7532738d750252c00e649890c694ee30Brian Wellington HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
5455f30a7532738d750252c00e649890c694ee30Brian Wellington case insensitive.
e2fd12f3a020ca8c5de168a44fb72e339cdaa3e9Brian Wellington </p>
e2fd12f3a020ca8c5de168a44fb72e339cdaa3e9Brian Wellington<p>
e2fd12f3a020ca8c5de168a44fb72e339cdaa3e9Brian Wellington If no algorithm is specified, then RSASHA1 will be used by
cf74d05a50e342e5b3870005c04ae5ed8013ab3eBrian Wellington default, unless the <code class="option">-3</code> option is specified,
cf74d05a50e342e5b3870005c04ae5ed8013ab3eBrian Wellington in which case NSEC3RSASHA1 will be used instead. (If
cf74d05a50e342e5b3870005c04ae5ed8013ab3eBrian Wellington <code class="option">-3</code> is used and an algorithm is specified,
cf74d05a50e342e5b3870005c04ae5ed8013ab3eBrian Wellington that algorithm will be checked for compatibility with NSEC3.)
2ae4dd0dbd50b3159476537c60ccdc8b64364356Mark Andrews </p>
89d03d4715120fd0c968775bf0724b5a2a647539Mark Andrews<p>
2ae4dd0dbd50b3159476537c60ccdc8b64364356Mark Andrews Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
4fbd6a13a5ba6ec1e9bd080cba86c74b3b92c894Mark Andrews algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
761a21dfab558235030ccfc3d61979146e2cf4b5Mark Andrews mandatory.
f3ac8ee19231ae3018ec21756f19b1bd639ce7e7Andreas Gustafsson </p>
f3ac8ee19231ae3018ec21756f19b1bd639ce7e7Andreas Gustafsson<p>
f3ac8ee19231ae3018ec21756f19b1bd639ce7e7Andreas Gustafsson Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
f3ac8ee19231ae3018ec21756f19b1bd639ce7e7Andreas Gustafsson automatically set the -T KEY option.
0b135de5a52acec5bb42f96b4e79484d1629fd93Brian Wellington </p>
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson</dd>
5ce23ccf3f324dc90ab9b4426b1da6284b0e2abfAndreas Gustafsson<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
5ce23ccf3f324dc90ab9b4426b1da6284b0e2abfAndreas Gustafsson<dd>
5ce23ccf3f324dc90ab9b4426b1da6284b0e2abfAndreas Gustafsson<p>
5ce23ccf3f324dc90ab9b4426b1da6284b0e2abfAndreas Gustafsson Specifies the number of bits in the key. The choice of key
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson size depends on the algorithm used. RSA keys must be
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson between 512 and 2048 bits. Diffie Hellman keys must be between
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson 128 and 4096 bits. DSA keys must be between 512 and 1024
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson bits and an exact multiple of 64. HMAC keys must be
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson between 1 and 512 bits. Elliptic curve algorithms don't need
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson this parameter.
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson </p>
508d17362c2c43ddf95ddc87ae6a8c5f32f35323Andreas Gustafsson<p>
e7a4f58d55042cbc981a70b5071aaea46b9ebf7fAndreas Gustafsson The key size does not need to be specified if using a default
e7a4f58d55042cbc981a70b5071aaea46b9ebf7fAndreas Gustafsson algorithm. The default key size is 1024 bits for zone signing
e7a4f58d55042cbc981a70b5071aaea46b9ebf7fAndreas Gustafsson keys (ZSKs) and 2048 bits for key signing keys (KSKs,
e7a4f58d55042cbc981a70b5071aaea46b9ebf7fAndreas Gustafsson generated with <code class="option">-f KSK</code>). However, if an
5fdc9aaf401f6816df65d0e9cf701872f345c558Andreas Gustafsson algorithm is explicitly specified with the <code class="option">-a</code>,
5fdc9aaf401f6816df65d0e9cf701872f345c558Andreas Gustafsson then there is no default key size, and the <code class="option">-b</code>
5fdc9aaf401f6816df65d0e9cf701872f345c558Andreas Gustafsson must be used.
5fdc9aaf401f6816df65d0e9cf701872f345c558Andreas Gustafsson </p>
6060b0ac76667afae3c9132ab6e3568a7a693f5dAndreas Gustafsson</dd>
6060b0ac76667afae3c9132ab6e3568a7a693f5dAndreas Gustafsson<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
50097b38c075be55a73bb3737d091c503c70061dBrian Wellington<dd><p>
50097b38c075be55a73bb3737d091c503c70061dBrian Wellington Specifies the owner type of the key. The value of
af1a99a13d73126760b755d63ff7ef8c28ca9070Bob Halley <code class="option">nametype</code> must either be ZONE (for a DNSSEC
af1a99a13d73126760b755d63ff7ef8c28ca9070Bob Halley zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
af1a99a13d73126760b755d63ff7ef8c28ca9070Bob Halley a host (KEY)),
af1a99a13d73126760b755d63ff7ef8c28ca9070Bob Halley USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
751aa24c98fea02215cad95a08411af547d70e41Bob Halley These values are case insensitive. Defaults to ZONE for DNSKEY
fd5847ef0954117d5f905dbbfb68f1e67e4f285fAndreas Gustafsson generation.
fd5847ef0954117d5f905dbbfb68f1e67e4f285fAndreas Gustafsson </p></dd>
fd5847ef0954117d5f905dbbfb68f1e67e4f285fAndreas Gustafsson<dt><span class="term">-3</span></dt>
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson<dd><p>
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson Use an NSEC3-capable algorithm to generate a DNSSEC key.
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson If this option is used and no algorithm is explicitly
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson set on the command line, NSEC3RSASHA1 will be used by
82e991b8ed4e0ed3b010d191e0cadfd60226c2d9Andreas Gustafsson default. Note that RSASHA256, RSASHA512, ECCGOST,
69d44b2f5ac8e35bdb0b80aeb304f5cb62197892Mark Andrews ECDSAP256SHA256 and ECDSAP384SHA384 algorithms
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson are NSEC3-capable.
69d44b2f5ac8e35bdb0b80aeb304f5cb62197892Mark Andrews </p></dd>
f08f3c6caeb8460cb679a8687f61da61fff69fb0Mark Andrews<dt><span class="term">-C</span></dt>
69d44b2f5ac8e35bdb0b80aeb304f5cb62197892Mark Andrews<dd><p>
3242899a56da9c245956979d5be9c92b2cf0ee24Andreas Gustafsson Compatibility mode: generates an old-style key, without
8fbd23c0aaacdde1348b6457c5db14c433096fd2Andreas Gustafsson any metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
8fbd23c0aaacdde1348b6457c5db14c433096fd2Andreas Gustafsson will include the key's creation date in the metadata stored
8fbd23c0aaacdde1348b6457c5db14c433096fd2Andreas Gustafsson with the private key, and other dates may be set there as well
5f539d5fc68ca056bd1791e3156b0fe6b28cde16Brian Wellington (publication date, activation date, etc). Keys that include
5f539d5fc68ca056bd1791e3156b0fe6b28cde16Brian Wellington this data may be incompatible with older versions of BIND; the
5f539d5fc68ca056bd1791e3156b0fe6b28cde16Brian Wellington <code class="option">-C</code> option suppresses them.
76477bd0e0a8f150f06f45c347d286b782cfa679Brian Wellington </p></dd>
76477bd0e0a8f150f06f45c347d286b782cfa679Brian Wellington<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
76477bd0e0a8f150f06f45c347d286b782cfa679Brian Wellington<dd><p>
76477bd0e0a8f150f06f45c347d286b782cfa679Brian Wellington Indicates that the DNS record containing the key should have
e491ef29043ae77d3d78fb7a59328f143fcf70feAndreas Gustafsson the specified class. If not specified, class IN is used.
e491ef29043ae77d3d78fb7a59328f143fcf70feAndreas Gustafsson </p></dd>
e491ef29043ae77d3d78fb7a59328f143fcf70feAndreas Gustafsson<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
e491ef29043ae77d3d78fb7a59328f143fcf70feAndreas Gustafsson<dd>
1a286a6613d385b443030a8c932e40ac9e9c301fBob Halley<p>
1a286a6613d385b443030a8c932e40ac9e9c301fBob Halley Specifies the cryptographic hardware to use, when applicable.
1a286a6613d385b443030a8c932e40ac9e9c301fBob Halley </p>
1a286a6613d385b443030a8c932e40ac9e9c301fBob Halley<p>
1a286a6613d385b443030a8c932e40ac9e9c301fBob Halley When BIND is built with OpenSSL PKCS#11 support, this defaults
3242899a56da9c245956979d5be9c92b2cf0ee24Andreas Gustafsson to the string "pkcs11", which identifies an OpenSSL engine
3242899a56da9c245956979d5be9c92b2cf0ee24Andreas Gustafsson that can drive a cryptographic accelerator or hardware service
3242899a56da9c245956979d5be9c92b2cf0ee24Andreas Gustafsson module. When BIND is built with native PKCS#11 cryptography
ecaedd50f4e6b8cff110f9981a0a33a34269d421Mark Andrews (--enable-native-pkcs11), it defaults to the path of the PKCS#11
9ffcab1e9a398e431c10c9936c28e4166c2e82e0Andreas Gustafsson provider library specified via "--with-pkcs11".
296253a3b9dec61190cce77e8b551e05ff514fcdAndreas Gustafsson </p>
de8717a7218a4f034144ad7b8755ad43e3fd45c9David Lawrence</dd>
de8717a7218a4f034144ad7b8755ad43e3fd45c9David Lawrence<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
de8717a7218a4f034144ad7b8755ad43e3fd45c9David Lawrence<dd><p>
6f115bdb61672871bd822bdcd09cb1a3aad38aa0David Lawrence Set the specified flag in the flag field of the KEY/DNSKEY record.
6f115bdb61672871bd822bdcd09cb1a3aad38aa0David Lawrence The only recognized flags are KSK (Key Signing Key) and REVOKE.
6f115bdb61672871bd822bdcd09cb1a3aad38aa0David Lawrence </p></dd>
1ac6cf2f7ae95e4c915cba7038e61930d7c4ba2aAndreas Gustafsson<dt><span class="term">-G</span></dt>
6f115bdb61672871bd822bdcd09cb1a3aad38aa0David Lawrence<dd><p>
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson Generate a key, but do not publish it or sign with it. This
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson option is incompatible with -P and -A.
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson </p></dd>
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson<dt><span class="term">-g <em class="replaceable"><code>generator</code></em></span></dt>
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson<dd><p>
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson If generating a Diffie Hellman key, use this generator.
5e194abb5b548524e5c0fd2bb4627ec698b75e2bAndreas Gustafsson Allowed values are 2 and 5. If no generator
09ae77ca30eb17ee32d3f7720ca796a72259cde6Andreas Gustafsson is specified, a known prime from RFC 2539 will be used
09ae77ca30eb17ee32d3f7720ca796a72259cde6Andreas Gustafsson if possible; otherwise the default is 2.
09ae77ca30eb17ee32d3f7720ca796a72259cde6Andreas Gustafsson </p></dd>
47afc27c28aef95d94e8d1296498ba57a5f00b25Brian Wellington<dt><span class="term">-h</span></dt>
cedd0ab1e812ec7cf05d57c3e602db41b79f0a2aAndreas Gustafsson<dd><p>
8c3989000a19f88415d094eb5984f7cf6ba2340cBrian Wellington Prints a short summary of the options and arguments to
8c3989000a19f88415d094eb5984f7cf6ba2340cBrian Wellington <span class="command"><strong>dnssec-keygen</strong></span>.
8c3989000a19f88415d094eb5984f7cf6ba2340cBrian Wellington </p></dd>
ac6afcd0caf72aaa2a537e0003de30b363b4a68bBrian Wellington<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
ac6afcd0caf72aaa2a537e0003de30b363b4a68bBrian Wellington<dd><p>
ac6afcd0caf72aaa2a537e0003de30b363b4a68bBrian Wellington Sets the directory in which the key files are to be written.
c20ffa38dee7efa0dc01822d4bac5e41729b9b61Brian Wellington </p></dd>
c20ffa38dee7efa0dc01822d4bac5e41729b9b61Brian Wellington<dt><span class="term">-k</span></dt>
9ffcab1e9a398e431c10c9936c28e4166c2e82e0Andreas Gustafsson<dd><p>
9ffcab1e9a398e431c10c9936c28e4166c2e82e0Andreas Gustafsson Deprecated in favor of -T KEY.
9ffcab1e9a398e431c10c9936c28e4166c2e82e0Andreas Gustafsson </p></dd>
2b7a77a68e27fc7991a857d403cb34b2ae90fc0bMark Andrews<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
4df51a8f53381d57b3dd75dd84615abd4cf9e969Andreas Gustafsson<dd><p>
0c9dd74fecd876563b7f0e4662243ff026b59622Andreas Gustafsson Sets the default TTL to use for this key when it is converted
76873278a44e5ac36ac61b070035ca6d1f353f59Andreas Gustafsson into a DNSKEY RR. If the key is imported into a zone,
0c9dd74fecd876563b7f0e4662243ff026b59622Andreas Gustafsson this is the TTL that will be used for it, unless there was
aed6a8ed2e706404ccca0f31faf110fd6efd34e6Andreas Gustafsson already a DNSKEY RRset in place, in which case the existing TTL
aed6a8ed2e706404ccca0f31faf110fd6efd34e6Andreas Gustafsson would take precedence. If this value is not set and there
aed6a8ed2e706404ccca0f31faf110fd6efd34e6Andreas Gustafsson is no existing DNSKEY RRset, the TTL will default to the
aed6a8ed2e706404ccca0f31faf110fd6efd34e6Andreas Gustafsson SOA TTL. Setting the default TTL to <code class="literal">0</code>
f8b3c627949bd4bc2f6aafb3dab2f56e3aa9ba06Brian Wellington or <code class="literal">none</code> is the same as leaving it unset.
f8b3c627949bd4bc2f6aafb3dab2f56e3aa9ba06Brian Wellington </p></dd>
f8b3c627949bd4bc2f6aafb3dab2f56e3aa9ba06Brian Wellington<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
f8b3c627949bd4bc2f6aafb3dab2f56e3aa9ba06Brian Wellington<dd><p>
55ddb88e53838693370c213930beda1652b8a583Brian Wellington Sets the protocol value for the generated key. The protocol
55ddb88e53838693370c213930beda1652b8a583Brian Wellington is a number between 0 and 255. The default is 3 (DNSSEC).
55ddb88e53838693370c213930beda1652b8a583Brian Wellington Other possible values for this argument are listed in
daad43e5a4e83bd3c055632799ab67e269467db0Brian Wellington RFC 2535 and its successors.
daad43e5a4e83bd3c055632799ab67e269467db0Brian Wellington </p></dd>
daad43e5a4e83bd3c055632799ab67e269467db0Brian Wellington<dt><span class="term">-q</span></dt>
3efd6904134ef6c4866a633eabeb55d1c86be7bbBrian Wellington<dd><p>
3efd6904134ef6c4866a633eabeb55d1c86be7bbBrian Wellington Quiet mode: Suppresses unnecessary output, including
3efd6904134ef6c4866a633eabeb55d1c86be7bbBrian Wellington progress indication. Without this option, when
70d08aea0a693c6ca62c2f7bb33bfddf9e427601Brian Wellington <span class="command"><strong>dnssec-keygen</strong></span> is run interactively
61470ed14b20c55c0730461165faa582a3775eb8Mark Andrews to generate an RSA or DSA key pair, it will print a string
70d08aea0a693c6ca62c2f7bb33bfddf9e427601Brian Wellington of symbols to <code class="filename">stderr</code> indicating the
907620b5e0d898da324192cbbe5a5b518f55d175Bob Halley progress of the key generation. A '.' indicates that a
907620b5e0d898da324192cbbe5a5b518f55d175Bob Halley random number has been found which passed an initial
907620b5e0d898da324192cbbe5a5b518f55d175Bob Halley sieve test; '+' means a number has passed a single
2c9db9314993504064c1a71f4a059ff9493a75caBrian Wellington round of the Miller-Rabin primality test; a space
2c9db9314993504064c1a71f4a059ff9493a75caBrian Wellington means that the number has passed all the tests and is
2c9db9314993504064c1a71f4a059ff9493a75caBrian Wellington a satisfactory key.
672056d560d973cac1c0d02f087e059eef8f948fBrian Wellington </p></dd>
672056d560d973cac1c0d02f087e059eef8f948fBrian Wellington<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
9027e1bcf1b245226e3053a75d16c5351d7e60caDavid Lawrence<dd><p>
9027e1bcf1b245226e3053a75d16c5351d7e60caDavid Lawrence Specifies the source of randomness. If the operating
9027e1bcf1b245226e3053a75d16c5351d7e60caDavid Lawrence system does not provide a <code class="filename">/dev/random</code>
9027e1bcf1b245226e3053a75d16c5351d7e60caDavid Lawrence or equivalent device, the default source of randomness
9027e1bcf1b245226e3053a75d16c5351d7e60caDavid Lawrence is keyboard input. <code class="filename">randomdev</code>
668f8d91db59f4dd89a0b54206f87879354339f5Brian Wellington specifies
668f8d91db59f4dd89a0b54206f87879354339f5Brian Wellington the name of a character device or file containing random
d7ba3622ffa20c653ef6c8cfae42d8cd26465b7fBrian Wellington data to be used instead of the default. The special value
d7ba3622ffa20c653ef6c8cfae42d8cd26465b7fBrian Wellington <code class="filename">keyboard</code> indicates that keyboard
d7ba3622ffa20c653ef6c8cfae42d8cd26465b7fBrian Wellington input should be used.
c0968380c4fb0b8196aafb8de225531bd847bb6dBrian Wellington </p></dd>
c0968380c4fb0b8196aafb8de225531bd847bb6dBrian Wellington<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
c0968380c4fb0b8196aafb8de225531bd847bb6dBrian Wellington<dd><p>
c0968380c4fb0b8196aafb8de225531bd847bb6dBrian Wellington Create a new key which is an explicit successor to an
c0968380c4fb0b8196aafb8de225531bd847bb6dBrian Wellington existing key. The name, algorithm, size, and type of the
1d92d8a2456b23842a649b6104c60a9d6ea25333Brian Wellington key will be set to match the existing key. The activation
1d92d8a2456b23842a649b6104c60a9d6ea25333Brian Wellington date of the new key will be set to the inactivation date of
1d92d8a2456b23842a649b6104c60a9d6ea25333Brian Wellington the existing one. The publication date will be set to the
c1ff0308f3f67bf148f96ca952db081eb5fd8383Brian Wellington activation date minus the prepublication interval, which
b879ed05f4fb8209add6c19a509c984b6c8b3a98Andreas Gustafsson defaults to 30 days.
b52a5b063050f209b0f47379178a1e7ae7404624Andreas Gustafsson </p></dd>
b52a5b063050f209b0f47379178a1e7ae7404624Andreas Gustafsson<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
b52a5b063050f209b0f47379178a1e7ae7404624Andreas Gustafsson<dd><p>
34613b2e39478a83076f6a626a4b855cebb19533Andreas Gustafsson Specifies the strength value of the key. The strength is
34613b2e39478a83076f6a626a4b855cebb19533Andreas Gustafsson a number between 0 and 15, and currently has no defined
34613b2e39478a83076f6a626a4b855cebb19533Andreas Gustafsson purpose in DNSSEC.
34613b2e39478a83076f6a626a4b855cebb19533Andreas Gustafsson </p></dd>
eb059776a206e9be778de0f196a0304b558a779cAndreas Gustafsson<dt><span class="term">-T <em class="replaceable"><code>rrtype</code></em></span></dt>
6eccf5bd07eb9abf65cc08fec4a8fc97b62c0e1bBrian Wellington<dd>
6eccf5bd07eb9abf65cc08fec4a8fc97b62c0e1bBrian Wellington<p>
6eccf5bd07eb9abf65cc08fec4a8fc97b62c0e1bBrian Wellington Specifies the resource record type to use for the key.
3d1483d86dce11fffd03c5b6c93be2e689f522abAndreas Gustafsson <code class="option">rrtype</code> must be either DNSKEY or KEY. The
3d1483d86dce11fffd03c5b6c93be2e689f522abAndreas Gustafsson default is DNSKEY when using a DNSSEC algorithm, but it can be
3bd8e7cf1c082cd1021e5a6cae1cf21911217858Brian Wellington overridden to KEY for use with SIG(0).
3d1483d86dce11fffd03c5b6c93be2e689f522abAndreas Gustafsson </p>
3d1483d86dce11fffd03c5b6c93be2e689f522abAndreas Gustafsson<p>
b8a85202af814468421a6541b4c935bd14773c53Brian Wellington </p>
b879ed05f4fb8209add6c19a509c984b6c8b3a98Andreas Gustafsson<p>
b879ed05f4fb8209add6c19a509c984b6c8b3a98Andreas Gustafsson Using any TSIG algorithm (HMAC-* or DH) forces this option
b879ed05f4fb8209add6c19a509c984b6c8b3a98Andreas Gustafsson to KEY.
48565891e8f2f8c77b87908b4893f693a08e9ba9Brian Wellington </p>
48565891e8f2f8c77b87908b4893f693a08e9ba9Brian Wellington</dd>
4c03e69ab845f703c1ffa3b7772938ca98cce44dAndreas Gustafsson<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
b0390aab30438a13f533cccae9389945214b1421Brian Wellington<dd><p>
b0390aab30438a13f533cccae9389945214b1421Brian Wellington Indicates the use of the key. <code class="option">type</code> must be
b0390aab30438a13f533cccae9389945214b1421Brian Wellington one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
b0390aab30438a13f533cccae9389945214b1421Brian Wellington is AUTHCONF. AUTH refers to the ability to authenticate
eb059776a206e9be778de0f196a0304b558a779cAndreas Gustafsson data, and CONF the ability to encrypt data.
54d64c7994d01da590462ecc56faf1a87fc4abb9Brian Wellington </p></dd>
4c03e69ab845f703c1ffa3b7772938ca98cce44dAndreas Gustafsson<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
4c03e69ab845f703c1ffa3b7772938ca98cce44dAndreas Gustafsson<dd><p>
4c03e69ab845f703c1ffa3b7772938ca98cce44dAndreas Gustafsson Sets the debugging level.
225a66da7ea2671a3e4db3cc4337f97ff67be647Brian Wellington </p></dd>
225a66da7ea2671a3e4db3cc4337f97ff67be647Brian Wellington<dt><span class="term">-V</span></dt>
91e35ded544576b671606779143d7fbffaf451d2Andreas Gustafsson<dd><p>
225a66da7ea2671a3e4db3cc4337f97ff67be647Brian Wellington Prints version information.
d9112843333472bb7700c02a10d18e2b253b2708Bob Halley </p></dd>
279de54fe3a0ac10b64762b18a4569c07b15d742Andreas Gustafsson</dl></div>
279de54fe3a0ac10b64762b18a4569c07b15d742Andreas Gustafsson</div>
279de54fe3a0ac10b64762b18a4569c07b15d742Andreas Gustafsson<div class="refsection">
279de54fe3a0ac10b64762b18a4569c07b15d742Andreas Gustafsson<a name="id-1.14.11.9"></a><h2>TIMING OPTIONS</h2>
279de54fe3a0ac10b64762b18a4569c07b15d742Andreas Gustafsson<p>
04cb6056a6539539e0fc2ed695298f7fa7b1d632Brian Wellington Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
04cb6056a6539539e0fc2ed695298f7fa7b1d632Brian Wellington If the argument begins with a '+' or '-', it is interpreted as
17789c880460c0bca3f3693c759be2214b936e69Brian Wellington an offset from the present time. For convenience, if such an offset
55b62439233d930152690b9eba97b06d9dc13d23Mark Andrews is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
55b62439233d930152690b9eba97b06d9dc13d23Mark Andrews then the offset is computed in years (defined as 365 24-hour days,
02e7e0ba65a26a5f8728b0ee256f7253795cf839Brian Wellington ignoring leap years), months (defined as 30 24-hour days), weeks,
123a3dddc94534d3a6c6f81c118a5b63dc5994c3Andreas Gustafsson days, hours, or minutes, respectively. Without a suffix, the offset
590233519e14f3cf49840a93d2648d5560dd957eDavid Lawrence is computed in seconds. To explicitly prevent a date from being
590233519e14f3cf49840a93d2648d5560dd957eDavid Lawrence set, use 'none' or 'never'.
590233519e14f3cf49840a93d2648d5560dd957eDavid Lawrence </p>
590233519e14f3cf49840a93d2648d5560dd957eDavid Lawrence<div class="variablelist"><dl class="variablelist">
590233519e14f3cf49840a93d2648d5560dd957eDavid Lawrence<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
123a3dddc94534d3a6c6f81c118a5b63dc5994c3Andreas Gustafsson<dd><p>
123a3dddc94534d3a6c6f81c118a5b63dc5994c3Andreas Gustafsson Sets the date on which a key is to be published to the zone.
123a3dddc94534d3a6c6f81c118a5b63dc5994c3Andreas Gustafsson After that date, the key will be included in the zone but will
123a3dddc94534d3a6c6f81c118a5b63dc5994c3Andreas Gustafsson not be used to sign it. If not set, and if the -G option has
5ea0d11ca45bfd1ea9db8db07f18fbb02f500661Brian Wellington not been used, the default is "now".
88a790c39176f72a8f98f134b83df92e09a8c56bAndreas Gustafsson </p></dd>
5ea0d11ca45bfd1ea9db8db07f18fbb02f500661Brian Wellington<dt><span class="term">-P sync <em class="replaceable"><code>date/offset</code></em></span></dt>
d25dd5b0567f67ecf40b7ed1cb20e0dce7b41c49Brian Wellington<dd><p>
d25dd5b0567f67ecf40b7ed1cb20e0dce7b41c49Brian Wellington Sets the date on which CDS and CDNSKEY records that match this
d25dd5b0567f67ecf40b7ed1cb20e0dce7b41c49Brian Wellington key are to be published to the zone.
9ac7076ebad044afb15e9e2687e3696868778538Mark Andrews </p></dd>
9ac7076ebad044afb15e9e2687e3696868778538Mark Andrews<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
7c058f1c384ebdba74231111f9358cf08109a5dbBob Halley<dd><p>
7c058f1c384ebdba74231111f9358cf08109a5dbBob Halley Sets the date on which the key is to be activated. After that
7c058f1c384ebdba74231111f9358cf08109a5dbBob Halley date, the key will be included in the zone and used to sign
7c058f1c384ebdba74231111f9358cf08109a5dbBob Halley it. If not set, and if the -G option has not been used, the
76b3ec5e0c3ae856bc1000270bf3df13580673ebBrian Wellington default is "now". If set, if and -P is not set, then
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley the publication date will be set to the activation date
4e3f8e480f220ef8a87fd28d02f9001b8fc6f423Bob Halley minus the prepublication interval.
4e3f8e480f220ef8a87fd28d02f9001b8fc6f423Bob Halley </p></dd>
f9e1aa0c440b6c6938967ed5356ec025ea40502eBrian Wellington<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
f9e1aa0c440b6c6938967ed5356ec025ea40502eBrian Wellington<dd><p>
f9e1aa0c440b6c6938967ed5356ec025ea40502eBrian Wellington Sets the date on which the key is to be revoked. After that
4e3f8e480f220ef8a87fd28d02f9001b8fc6f423Bob Halley date, the key will be flagged as revoked. It will be included
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson in the zone and will be used to sign it.
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson </p></dd>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson<dd><p>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson Sets the date on which the key is to be retired. After that
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson date, the key will still be included in the zone, but it
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson will not be used to sign it.
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson </p></dd>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson<dd><p>
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson Sets the date on which the key is to be deleted. After that
dc2e09d48b49d96a0572a971180718f680140cf0Andreas Gustafsson date, the key will no longer be included in the zone. (It
90c099e88e9f16bfee9edee3ac1a51fc98843772Brian Wellington may remain in the key repository, however.)
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley </p></dd>
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley<dt><span class="term">-D sync <em class="replaceable"><code>date/offset</code></em></span></dt>
620de5a4b1f23dc9b4ec30d30c0607ff389be0daBob Halley<dd><p>
68b952dc98a9e02b269c0712da120cd773679652Brian Wellington Sets the date on which the CDS and CDNSKEY records that match this
68b952dc98a9e02b269c0712da120cd773679652Brian Wellington key are to be deleted.
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson </p></dd>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson<dd>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson<p>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson Sets the prepublication interval for a key. If set, then
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson the publication and activation dates must be separated by at least
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson this much time. If the activation date is specified but the
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson publication date isn't, then the publication date will default
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson to this much time before the activation date; conversely, if
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson the publication date is specified but activation date isn't,
ed0a4f1a302a5e543a9a2e4f8e61ca8a0673c6a7Mark Andrews then activation will be set to this much time after publication.
ed0a4f1a302a5e543a9a2e4f8e61ca8a0673c6a7Mark Andrews </p>
a93cf7e83be621d3d68f51e37121a47a70a6757bMark Andrews<p>
a93cf7e83be621d3d68f51e37121a47a70a6757bMark Andrews If the key is being created as an explicit successor to another
a93cf7e83be621d3d68f51e37121a47a70a6757bMark Andrews key, then the default prepublication interval is 30 days;
a97b72bac75dd2b4294108f59e1273f50495583cAndreas Gustafsson otherwise it is zero.
c05eeed3c915d55a4949f5c2ce8700a0b0f9381bAndreas Gustafsson </p>
1c1156b6e71555e593ed4bbca2284055c9f6fa45Andreas Gustafsson<p>
1c1156b6e71555e593ed4bbca2284055c9f6fa45Andreas Gustafsson As with date offsets, if the argument is followed by one of
c05eeed3c915d55a4949f5c2ce8700a0b0f9381bAndreas Gustafsson the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
c05eeed3c915d55a4949f5c2ce8700a0b0f9381bAndreas Gustafsson interval is measured in years, months, weeks, days, hours,
3bb043a8b8b15eece3794ec31ad0ccab103a1c21Brian Wellington or minutes, respectively. Without a suffix, the interval is
3bb043a8b8b15eece3794ec31ad0ccab103a1c21Brian Wellington measured in seconds.
3bb043a8b8b15eece3794ec31ad0ccab103a1c21Brian Wellington </p>
14c615e979f674aa61b0ca65c6a252009e521dd8Brian Wellington</dd>
3bb043a8b8b15eece3794ec31ad0ccab103a1c21Brian Wellington</dl></div>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson</div>
d1cc210d2091916df6f9858fae20a1c760f3b257Andreas Gustafsson<div class="refsection">
df0f58959ed82a2a43ca8d816ce9592541df9f2fMark Andrews<a name="id-1.14.11.10"></a><h2>GENERATED KEYS</h2>
4d35b6836eb57387a9da6b103331b59cc988b827Mark Andrews<p>
903e9d41ef730f098d38da9588f2824f37b7d73cMark Andrews When <span class="command"><strong>dnssec-keygen</strong></span> completes
f4b5a0f43481026ea27bd96e3584ca0e92542f0dBob Halley successfully,
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson it prints a string of the form <code class="filename">Knnnn.+aaa+iiiii</code>
f4b5a0f43481026ea27bd96e3584ca0e92542f0dBob Halley to the standard output. This is an identification string for
f4b5a0f43481026ea27bd96e3584ca0e92542f0dBob Halley the key it has generated.
f4b5a0f43481026ea27bd96e3584ca0e92542f0dBob Halley </p>
f4b5a0f43481026ea27bd96e3584ca0e92542f0dBob Halley<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
6211baaa66d7cac28a21b6426681e597ff04ca9eAndreas Gustafsson<li class="listitem"><p><code class="filename">nnnn</code> is the key name.
6211baaa66d7cac28a21b6426681e597ff04ca9eAndreas Gustafsson </p></li>
4e605108c6533c2ec6311ee7a466582392656dddAndreas Gustafsson<li class="listitem"><p><code class="filename">aaa</code> is the numeric representation
6211baaa66d7cac28a21b6426681e597ff04ca9eAndreas Gustafsson of the
ea544b0511a66bc5f3700d56a72dcd808fdf22e8Brian Wellington algorithm.
ea544b0511a66bc5f3700d56a72dcd808fdf22e8Brian Wellington </p></li>
762a538eed7f4de4c340090536553f9c73f6432aBrian Wellington<li class="listitem"><p><code class="filename">iiiii</code> is the key identifier (or
ea544b0511a66bc5f3700d56a72dcd808fdf22e8Brian Wellington footprint).
a012d6dbfb100390efa7d0d4be64ada0210b09ddBrian Wellington </p></li>
a012d6dbfb100390efa7d0d4be64ada0210b09ddBrian Wellington</ul></div>
a012d6dbfb100390efa7d0d4be64ada0210b09ddBrian Wellington<p><span class="command"><strong>dnssec-keygen</strong></span>
c44ab73a0f37fa8c8a52069ca20dd060492dbafdAndreas Gustafsson creates two files, with names based
7ae7d499f353549162ddcf6fed957ea21e4fa52bMark Andrews on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
c8d185ad5827bf2cf9982075e3336f680759a260Andreas Gustafsson contains the public key, and
1e50dad10da55802152d00d5573f8b7d49d752a6Bob Halley <code class="filename">Knnnn.+aaa+iiiii.private</code> contains the
1e50dad10da55802152d00d5573f8b7d49d752a6Bob Halley private
1e50dad10da55802152d00d5573f8b7d49d752a6Bob Halley key.
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson </p>
1e50dad10da55802152d00d5573f8b7d49d752a6Bob Halley<p>
c8d185ad5827bf2cf9982075e3336f680759a260Andreas Gustafsson The <code class="filename">.key</code> file contains a DNS KEY record
c8d185ad5827bf2cf9982075e3336f680759a260Andreas Gustafsson that
40c1177517ca5312371da6cc697d813576cfe5a8Andreas Gustafsson can be inserted into a zone file (directly or with a $INCLUDE
c8d185ad5827bf2cf9982075e3336f680759a260Andreas Gustafsson statement).
22cafd0ece9c8d22a1218f000afdbceda21fe8afBrian Wellington </p>
22cafd0ece9c8d22a1218f000afdbceda21fe8afBrian Wellington<p>
2cb74c5bc52ef415a771fafe0bf504eab609feadBrian Wellington The <code class="filename">.private</code> file contains
2cb74c5bc52ef415a771fafe0bf504eab609feadBrian Wellington algorithm-specific
3d60fe9bafbf633e3a7811c11227baebb17878a4Brian Wellington fields. For obvious security reasons, this file does not have
3d60fe9bafbf633e3a7811c11227baebb17878a4Brian Wellington general read permission.
218c8472e6c8c1a014e412615cc97bb93c0ef9c2Brian Wellington </p>
218c8472e6c8c1a014e412615cc97bb93c0ef9c2Brian Wellington<p>
218c8472e6c8c1a014e412615cc97bb93c0ef9c2Brian Wellington Both <code class="filename">.key</code> and <code class="filename">.private</code>
218c8472e6c8c1a014e412615cc97bb93c0ef9c2Brian Wellington files are generated for symmetric cryptography algorithms such as
f24c135e09214c3843a49fd32ebef2f6a436ba8eBrian Wellington HMAC-MD5, even though the public and private key are equivalent.
f24c135e09214c3843a49fd32ebef2f6a436ba8eBrian Wellington </p>
d77312050f1fb1d41b450d4fe6908ea155264d08Brian Wellington</div>
f24c135e09214c3843a49fd32ebef2f6a436ba8eBrian Wellington<div class="refsection">
4b9f0fd0791cb9cb31087789a03fa3a28dd4b583Andreas Gustafsson<a name="id-1.14.11.11"></a><h2>EXAMPLE</h2>
02940eaf0f732c28c0b39ed114a3803074a80138Andreas Gustafsson<p>
02940eaf0f732c28c0b39ed114a3803074a80138Andreas Gustafsson To generate a 768-bit DSA key for the domain
02940eaf0f732c28c0b39ed114a3803074a80138Andreas Gustafsson <strong class="userinput"><code>example.com</code></strong>, the following command would be
dc1453b15d6656cd0661d5bec56359efa649268dAndreas Gustafsson issued:
9a7d163f6f305d48771b4c56d8d18efc6dfc8fc3Mark Andrews </p>
80aba3d49a872ca11d7cf8550c3a993162e7939fMark Andrews<p><strong class="userinput"><code>dnssec-keygen -a DSA -b 768 -n ZONE example.com</code></strong>
31039b15173fb3e375269991920e4843f664457eMark Andrews </p>
31039b15173fb3e375269991920e4843f664457eMark Andrews<p>
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson The command would print a string of the form:
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson </p>
936af16e0dbac26c1ec2337e684ff6ca9b2fe1bbAndreas Gustafsson<p><strong class="userinput"><code>Kexample.com.+003+26160</code></strong>
aa23a35d81a9618a40c4a9b44be48009553e4777Andreas Gustafsson </p>
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson<p>
22457624d3e63e7cd255b4083cb435c16caea26dBob Halley In this example, <span class="command"><strong>dnssec-keygen</strong></span> creates
019fefd77d7e77f3c841808ab604f8ce31679d2dBrian Wellington the files <code class="filename">Kexample.com.+003+26160.key</code>
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson and
91425b5e7204b05165e2c5b244f3dad502f9627dBrian Wellington <code class="filename">Kexample.com.+003+26160.private</code>.
91425b5e7204b05165e2c5b244f3dad502f9627dBrian Wellington </p>
91425b5e7204b05165e2c5b244f3dad502f9627dBrian Wellington</div>
91425b5e7204b05165e2c5b244f3dad502f9627dBrian Wellington<div class="refsection">
b18a5b6730dcb062cf7f47c6b3cb909030b58f36Brian Wellington<a name="id-1.14.11.12"></a><h2>SEE ALSO</h2>
b18a5b6730dcb062cf7f47c6b3cb909030b58f36Brian Wellington<p><span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
e880677f633f726b7df11ba3e59d4406e22256aaMark Andrews <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
e880677f633f726b7df11ba3e59d4406e22256aaMark Andrews <em class="citetitle">RFC 2539</em>,
7e361074bc8a2df7a0891a7040eea02ca3a5e286Andreas Gustafsson <em class="citetitle">RFC 2845</em>,
328b080b4af258fdd4d3a2ea1558b48706bd8116Andreas Gustafsson <em class="citetitle">RFC 4034</em>.
328b080b4af258fdd4d3a2ea1558b48706bd8116Andreas Gustafsson </p>
328b080b4af258fdd4d3a2ea1558b48706bd8116Andreas Gustafsson</div>
328b080b4af258fdd4d3a2ea1558b48706bd8116Andreas Gustafsson</div>
328b080b4af258fdd4d3a2ea1558b48706bd8116Andreas Gustafsson<div class="navfooter">
9e560b59a722d06a62b5aed761e71fec72638a7cBrian Wellington<hr>
9e560b59a722d06a62b5aed761e71fec72638a7cBrian Wellington<table width="100%" summary="Navigation footer">
f91dc72b422479b5a0caf1fe54c4054d25ae6055Brian Wellington<tr>
f91dc72b422479b5a0caf1fe54c4054d25ae6055Brian Wellington<td width="40%" align="left">
7e361074bc8a2df7a0891a7040eea02ca3a5e286Andreas Gustafsson<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
7e361074bc8a2df7a0891a7040eea02ca3a5e286Andreas Gustafsson<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
7e361074bc8a2df7a0891a7040eea02ca3a5e286Andreas Gustafsson<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
d6b3d06db7ce3b9229dc30cc0e3a72ba2603da28Bob Halley</td>
0e7da7ac26cb234763ff03c3a9bc06e3c22e546fAndreas Gustafsson</tr>
d6b3d06db7ce3b9229dc30cc0e3a72ba2603da28Bob Halley<tr>
d6b3d06db7ce3b9229dc30cc0e3a72ba2603da28Bob Halley<td width="40%" align="left" valign="top">
8e68489885e744ab48907414b4199c36858c27ddMark Andrews<span class="application">dnssec-keyfromlabel</span>�</td>
8e68489885e744ab48907414b4199c36858c27ddMark Andrews<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
8e68489885e744ab48907414b4199c36858c27ddMark Andrews<td width="40%" align="right" valign="top">�<span class="application">dnssec-revoke</span>
c17c59662f0969a5e52e8b7529cbde1a7c746095Andreas Gustafsson</td>
c17c59662f0969a5e52e8b7529cbde1a7c746095Andreas Gustafsson</tr>
c17c59662f0969a5e52e8b7529cbde1a7c746095Andreas Gustafsson</table>
c17c59662f0969a5e52e8b7529cbde1a7c746095Andreas Gustafsson</div>
ec4f7c6d0f0cfc72bcecdb22bf59890d590218d6Mark Andrews<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.0rc1</p>
d8d95c7d2eae28c5adbde097e88efa115bae6f35Andreas Gustafsson</body>
651421a5db8a9edf39c76fd8cf859409eb8c373bAndreas Gustafsson</html>
651421a5db8a9edf39c76fd8cf859409eb8c373bAndreas Gustafsson