man.dnssec-keygen.html revision 603de7394f5a466ea39a33a6eea2022885ec3f87
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Copyright (C) 2000-2003 Internet Software Consortium.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - Permission to use, copy, modify, and/or distribute this software for any
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - purpose with or without fee is hereby granted, provided that the above
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - copyright notice and this permission notice appear in all copies.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster - PERFORMANCE OF THIS SOFTWARE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<!-- $Id$ -->
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<table width="100%" summary="Navigation header">
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<th width="60%" align="center">Manual pages</th>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span class="application">dnssec-keygen</span> — DNSSEC key generation tool</p>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-z</code>] {name}</p></div>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<p><span><strong class="command">dnssec-keygen</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster and RFC 4034. It can also generate keys for use with
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (Transaction Key) as defined in RFC 2930.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The <code class="option">name</code> of the key is specified on the command
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster line. For DNSSEC keys, this must match the name of the zone for
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster which the key is being generated.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Selects the cryptographic algorithm. For DNSSEC keys, the value
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ECDSAP256SHA256 or ECDSAP384SHA384.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster case insensitive.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If no algorithm is specified, then RSASHA1 will be used by
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster default, unless the <code class="option">-3</code> option is specified,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster in which case NSEC3RSASHA1 will be used instead. (If
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">-3</code> is used and an algorithm is specified,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster that algorithm will be checked for compatibility with NSEC3.)
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster automatically set the -T KEY option.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Specifies the number of bits in the key. The choice of key
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster size depends on the algorithm used. RSA keys must be
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster between 512 and 2048 bits. Diffie Hellman keys must be between
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster 128 and 4096 bits. DSA keys must be between 512 and 1024
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster bits and an exact multiple of 64. HMAC keys must be
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster between 1 and 512 bits. Elliptic curve algorithms don't need
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster this parameter.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The key size does not need to be specified if using a default
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster algorithm. The default key size is 1024 bits for zone signing
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster keys (ZSKs) and 2048 bits for key signing keys (KSKs,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster generated with <code class="option">-f KSK</code>). However, if an
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster algorithm is explicitly specified with the <code class="option">-a</code>,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster then there is no default key size, and the <code class="option">-b</code>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster must be used.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Specifies the owner type of the key. The value of
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">nametype</code> must either be ZONE (for a DNSSEC
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster a host (KEY)),
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster These values are case insensitive. Defaults to ZONE for DNSKEY
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Use an NSEC3-capable algorithm to generate a DNSSEC key.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If this option is used and no algorithm is explicitly
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster set on the command line, NSEC3RSASHA1 will be used by
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster default. Note that RSASHA256, RSASHA512, ECCGOST,
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster ECDSAP256SHA256 and ECDSAP384SHA384 algorithms
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster are NSEC3-capable.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Compatibility mode: generates an old-style key, without
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster any metadata. By default, <span><strong class="command">dnssec-keygen</strong></span>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster will include the key's creation date in the metadata stored
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster with the private key, and other dates may be set there as well
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (publication date, activation date, etc). Keys that include
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster this data may be incompatible with older versions of BIND; the
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <code class="option">-C</code> option suppresses them.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Indicates that the DNS record containing the key should have
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster the specified class. If not specified, class IN is used.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Specifies the cryptographic hardware to use, when applicable.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster When BIND is built with OpenSSL PKCS#11 support, this defaults
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster to the string "pkcs11", which identifies an OpenSSL engine
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster that can drive a cryptographic accelerator or hardware service
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster module. When BIND is built with native PKCS#11 cryptography
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster (--enable-native-pkcs11), it defaults to the path of the PKCS#11
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster provider library specified via "--with-pkcs11".
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Set the specified flag in the flag field of the KEY/DNSKEY record.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster The only recognized flags are KSK (Key Signing Key) and REVOKE.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Generate a key, but do not publish it or sign with it. This
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster option is incompatible with -P and -A.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-g <em class="replaceable"><code>generator</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster If generating a Diffie Hellman key, use this generator.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Allowed values are 2 and 5. If no generator
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster is specified, a known prime from RFC 2539 will be used
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster if possible; otherwise the default is 2.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Prints a short summary of the options and arguments to
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster <span><strong class="command">dnssec-keygen</strong></span>.
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
8af80418ba1ec431c8027fa9668e5678658d3611Allan Foster Sets the directory in which the key files are to be written.