man.dnssec-keygen.html revision 7717ec7a6a898cdd3c35cbfba66010b7304ffd9b
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg - Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - Copyright (C) 2000-2003 Internet Software Consortium.
16b55a35cff91315d261d1baa776138af465c4e4fuankg - Permission to use, copy, modify, and/or distribute this software for any
16b55a35cff91315d261d1baa776138af465c4e4fuankg - purpose with or without fee is hereby granted, provided that the above
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - copyright notice and this permission notice appear in all copies.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes - PERFORMANCE OF THIS SOFTWARE.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<!-- $Id: man.dnssec-keygen.html,v 1.184 2011/03/22 01:14:27 tbox Exp $ -->
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
16b55a35cff91315d261d1baa776138af465c4e4fuankg<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
16b55a35cff91315d261d1baa776138af465c4e4fuankg<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
16b55a35cff91315d261d1baa776138af465c4e4fuankg<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
16b55a35cff91315d261d1baa776138af465c4e4fuankg<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<p><span class="application">dnssec-keygen</span> — DNSSEC key generation tool</p>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
16b55a35cff91315d261d1baa776138af465c4e4fuankg<p><span><strong class="command">dnssec-keygen</strong></span>
16b55a35cff91315d261d1baa776138af465c4e4fuankg generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes and RFC 4034. It can also generate keys for use with
6f99e6278481df33e006c428d3d6de68a1ecd5d5fuankg TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes (Transaction Key) as defined in RFC 2930.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes The <code class="option">name</code> of the key is specified on the command
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes line. For DNSSEC keys, this must match the name of the zone for
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes which the key is being generated.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Selects the cryptographic algorithm. For DNSSEC keys, the value
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512 or ECCGOST.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes case insensitive.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes If no algorithm is specified, then RSASHA1 will be used by
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes default, unless the <code class="option">-3</code> option is specified,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes in which case NSEC3RSASHA1 will be used instead. (If
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <code class="option">-3</code> is used and an algorithm is specified,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes that algorithm will be checked for compatibility with NSEC3.)
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes automatically set the -T KEY option.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Specifies the number of bits in the key. The choice of key
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes size depends on the algorithm used. RSA keys must be
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes between 512 and 2048 bits. Diffie Hellman keys must be between
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes 128 and 4096 bits. DSA keys must be between 512 and 1024
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes bits and an exact multiple of 64. HMAC keys must be
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes between 1 and 512 bits.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes The key size does not need to be specified if using a default
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes algorithm. The default key size is 1024 bits for zone signing
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes keys (ZSK's) and 2048 bits for key signing keys (KSK's,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes generated with <code class="option">-f KSK</code>). However, if an
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes algorithm is explicitly specified with the <code class="option">-a</code>,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes then there is no default key size, and the <code class="option">-b</code>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes must be used.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Specifies the owner type of the key. The value of
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <code class="option">nametype</code> must either be ZONE (for a DNSSEC
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes a host (KEY)),
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes These values are case insensitive. Defaults to ZONE for DNSKEY
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Use an NSEC3-capable algorithm to generate a DNSSEC key.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes If this option is used and no algorithm is explicitly
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes set on the command line, NSEC3RSASHA1 will be used by
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes default. Note that RSASHA256, RSASHA512 and ECCGOST algorithms
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes are NSEC3-capable.
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg Compatibility mode: generates an old-style key, without
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes any metadata. By default, <span><strong class="command">dnssec-keygen</strong></span>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes will include the key's creation date in the metadata stored
16b55a35cff91315d261d1baa776138af465c4e4fuankg with the private key, and other dates may be set there as well
16b55a35cff91315d261d1baa776138af465c4e4fuankg (publication date, activation date, etc). Keys that include
16b55a35cff91315d261d1baa776138af465c4e4fuankg this data may be incompatible with older versions of BIND; the
b387b9d37fc71c534f4718777454a8f5a1169017fuankg <code class="option">-C</code> option suppresses them.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Indicates that the DNS record containing the key should have
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes the specified class. If not specified, class IN is used.
0b2a6b63977ab27352a0b525bdad1e1982a1c0b1bnicholes<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Uses a crypto hardware (OpenSSL engine) for random number
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg and, when supported, key generation. When compiled with PKCS#11
0662ed52e814f8f08ef0e09956413a792584eddffuankg support it defaults to pkcs11; the empty name resets it to
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes If generating an RSAMD5/RSASHA1 key, use a large exponent.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Set the specified flag in the flag field of the KEY/DNSKEY record.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes The only recognized flags are KSK (Key Signing Key) and REVOKE.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Generate a key, but do not publish it or sign with it. This
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes option is incompatible with -P and -A.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-g <em class="replaceable"><code>generator</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes If generating a Diffie Hellman key, use this generator.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Allowed values are 2 and 5. If no generator
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes is specified, a known prime from RFC 2539 will be used
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes if possible; otherwise the default is 2.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Prints a short summary of the options and arguments to
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <span><strong class="command">dnssec-keygen</strong></span>.
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg Sets the directory in which the key files are to be written.
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg Deprecated in favor of -T KEY.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the default TTL to use for this key when it is converted
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes into a DNSKEY RR. If the key is imported into a zone,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes this is the TTL that will be used for it, unless there was
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes already a DNSKEY RRset in place, in which case the existing TTL
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes would take precedence. Setting the default TTL to
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <code class="literal">0</code> or <code class="literal">none</code> removes it.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the protocol value for the generated key. The protocol
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes is a number between 0 and 255. The default is 3 (DNSSEC).
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Other possible values for this argument are listed in
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes RFC 2535 and its successors.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Quiet mode: Suppresses unnecessary output, including
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes progress indication. Without this option, when
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <span><strong class="command">dnssec-keygen</strong></span> is run interactively
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes to generate an RSA or DSA key pair, it will print a string
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes of symbols to <code class="filename">stderr</code> indicating the
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes progress of the key generation. A '.' indicates that a
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes random number has been found which passed an initial
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes sieve test; '+' means a number has passed a single
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes round of the Miller-Rabin primality test; a space
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes means that the number has passed all the tests and is
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes a satisfactory key.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
16b55a35cff91315d261d1baa776138af465c4e4fuankg Specifies the source of randomness. If the operating
16b55a35cff91315d261d1baa776138af465c4e4fuankg system does not provide a <code class="filename">/dev/random</code>
16b55a35cff91315d261d1baa776138af465c4e4fuankg or equivalent device, the default source of randomness
16b55a35cff91315d261d1baa776138af465c4e4fuankg is keyboard input. <code class="filename">randomdev</code>
16b55a35cff91315d261d1baa776138af465c4e4fuankg the name of a character device or file containing random
16b55a35cff91315d261d1baa776138af465c4e4fuankg data to be used instead of the default. The special value
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <code class="filename">keyboard</code> indicates that keyboard
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes input should be used.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Create a new key which is an explicit successor to an
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes existing key. The name, algorithm, size, and type of the
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes key will be set to match the existing key. The activation
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes date of the new key will be set to the inactivation date of
16b55a35cff91315d261d1baa776138af465c4e4fuankg the existing one. The publication date will be set to the
16b55a35cff91315d261d1baa776138af465c4e4fuankg activation date minus the prepublication interval, which
16b55a35cff91315d261d1baa776138af465c4e4fuankg defaults to 30 days.
16b55a35cff91315d261d1baa776138af465c4e4fuankg<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Specifies the strength value of the key. The strength is
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes a number between 0 and 15, and currently has no defined
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes purpose in DNSSEC.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-T <em class="replaceable"><code>rrtype</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Specifies the resource record type to use for the key.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes <code class="option">rrtype</code> must be either DNSKEY or KEY. The
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes default is DNSKEY when using a DNSSEC algorithm, but it can be
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes overridden to KEY for use with SIG(0).
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Using any TSIG algorithm (HMAC-* or DH) forces this option
8ffac2c334103c0336602aaede650cb578611151fuankg<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Indicates the use of the key. <code class="option">type</code> must be
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes is AUTHCONF. AUTH refers to the ability to authenticate
16b55a35cff91315d261d1baa776138af465c4e4fuankg data, and CONF the ability to encrypt data.
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg Sets the debugging level.
16b55a35cff91315d261d1baa776138af465c4e4fuankg Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
16b55a35cff91315d261d1baa776138af465c4e4fuankg If the argument begins with a '+' or '-', it is interpreted as
16b55a35cff91315d261d1baa776138af465c4e4fuankg an offset from the present time. For convenience, if such an offset
16b55a35cff91315d261d1baa776138af465c4e4fuankg is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
16b55a35cff91315d261d1baa776138af465c4e4fuankg then the offset is computed in years (defined as 365 24-hour days,
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg ignoring leap years), months (defined as 30 24-hour days), weeks,
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes days, hours, or minutes, respectively. Without a suffix, the offset
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes is computed in seconds.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg Sets the date on which a key is to be published to the zone.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes After that date, the key will be included in the zone but will
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes not be used to sign it. If not set, and if the -G option has
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes not been used, the default is "now".
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the date on which the key is to be activated. After that
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes date, the key will be included in the zone and used to sign
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes it. If not set, and if the -G option has not been used, the
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes default is "now".
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the date on which the key is to be revoked. After that
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes date, the key will be flagged as revoked. It will be included
ac7985784d08a3655291f24f711812b4d8b1cbcffuankg in the zone and will be used to sign it.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
f2f3f241c00a7a4bd597e57a19023940e072918abnicholes Sets the date on which the key is to be retired. After that
16b55a35cff91315d261d1baa776138af465c4e4fuankg date, the key will still be included in the zone, but it
16b55a35cff91315d261d1baa776138af465c4e4fuankg will not be used to sign it.
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the date on which the key is to be deleted. After that
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes date, the key will no longer be included in the zone. (It
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes may remain in the key repository, however.)
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes Sets the prepublication interval for a key. If set, then
0662ed52e814f8f08ef0e09956413a792584eddffuankg the publication and activation dates must be separated by at least
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes this much time. If the activation date is specified but the
e76fdcdfb8994ad70776526f50fa013b3e9a6033bnicholes publication date isn't, then the publication date will default