man.dnssec-keygen.html revision e62b9c9ce6413fb183c8116381e75dcd07ca5517
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<!--
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - Copyright (C) 2000-2003 Internet Software Consortium.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys -
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - Permission to use, copy, modify, and/or distribute this software for any
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - purpose with or without fee is hereby granted, provided that the above
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - copyright notice and this permission notice appear in all copies.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys -
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys - PERFORMANCE OF THIS SOFTWARE.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys-->
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<html>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<head>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<title>dnssec-keygen</title>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</head>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="navheader">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<table width="100%" summary="Navigation header">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<tr>
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll<td width="20%" align="left">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<th width="60%" align="center">Manual pages</th>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</td>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</tr>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</table>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<hr>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refentry">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refnamediv">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<h2>Name</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p><span class="application">dnssec-keygen</span> &#8212; DNSSEC key generation tool</p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refsynopsisdiv">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<h2>Synopsis</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k</code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-V</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refsection">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a name="id-1.14.10.7"></a><h2>DESCRIPTION</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p><span class="command"><strong>dnssec-keygen</strong></span>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys and RFC 4034. It can also generate keys for use with
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys (Transaction Key) as defined in RFC 2930.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys The <code class="option">name</code> of the key is specified on the command
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys line. For DNSSEC keys, this must match the name of the zone for
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys which the key is being generated.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refsection">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a name="id-1.14.10.8"></a><h2>OPTIONS</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="variablelist"><dl class="variablelist">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll<dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Selects the cryptographic algorithm. For DNSSEC keys, the value
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys ECDSAP256SHA256 or ECDSAP384SHA384.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys For TSIG/TKEY, the value must
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys case insensitive.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If no algorithm is specified, then RSASHA1 will be used by
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys default, unless the <code class="option">-3</code> option is specified,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys in which case NSEC3RSASHA1 will be used instead. (If
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <code class="option">-3</code> is used and an algorithm is specified,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys that algorithm will be checked for compatibility with NSEC3.)
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys mandatory.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys automatically set the -T KEY option.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd>
de6732348404877079e00a1631babd13d8a5ad14Wyllys Ingersoll<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the number of bits in the key. The choice of key
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys size depends on the algorithm used. RSA keys must be
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys between 512 and 2048 bits. Diffie Hellman keys must be between
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys 128 and 4096 bits. DSA keys must be between 512 and 1024
de6732348404877079e00a1631babd13d8a5ad14Wyllys Ingersoll bits and an exact multiple of 64. HMAC keys must be
de6732348404877079e00a1631babd13d8a5ad14Wyllys Ingersoll between 1 and 512 bits. Elliptic curve algorithms don't need
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys this parameter.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys The key size does not need to be specified if using a default
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys algorithm. The default key size is 1024 bits for zone signing
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys keys (ZSKs) and 2048 bits for key signing keys (KSKs,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys generated with <code class="option">-f KSK</code>). However, if an
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys algorithm is explicitly specified with the <code class="option">-a</code>,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys then there is no default key size, and the <code class="option">-b</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys must be used.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the owner type of the key. The value of
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <code class="option">nametype</code> must either be ZONE (for a DNSSEC
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys a host (KEY)),
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys These values are case insensitive. Defaults to ZONE for DNSKEY
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys generation.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-3</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Use an NSEC3-capable algorithm to generate a DNSSEC key.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If this option is used and no algorithm is explicitly
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys set on the command line, NSEC3RSASHA1 will be used by
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys default. Note that RSASHA256, RSASHA512, ECCGOST,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys ECDSAP256SHA256 and ECDSAP384SHA384 algorithms
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys are NSEC3-capable.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-C</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Compatibility mode: generates an old-style key, without
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys any metadata. By default, <span class="command"><strong>dnssec-keygen</strong></span>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys will include the key's creation date in the metadata stored
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys with the private key, and other dates may be set there as well
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys (publication date, activation date, etc). Keys that include
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys this data may be incompatible with older versions of BIND; the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <code class="option">-C</code> option suppresses them.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Indicates that the DNS record containing the key should have
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the specified class. If not specified, class IN is used.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the cryptographic hardware to use, when applicable.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys When BIND is built with OpenSSL PKCS#11 support, this defaults
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys to the string "pkcs11", which identifies an OpenSSL engine
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys that can drive a cryptographic accelerator or hardware service
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys module. When BIND is built with native PKCS#11 cryptography
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys (--enable-native-pkcs11), it defaults to the path of the PKCS#11
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll provider library specified via "--with-pkcs11".
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll </p>
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll</dd>
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Set the specified flag in the flag field of the KEY/DNSKEY record.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys The only recognized flags are KSK (Key Signing Key) and REVOKE.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-G</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Generate a key, but do not publish it or sign with it. This
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys option is incompatible with -P and -A.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-g <em class="replaceable"><code>generator</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If generating a Diffie Hellman key, use this generator.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Allowed values are 2 and 5. If no generator
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is specified, a known prime from RFC 2539 will be used
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys if possible; otherwise the default is 2.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-h</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Prints a short summary of the options and arguments to
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <span class="command"><strong>dnssec-keygen</strong></span>.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the directory in which the key files are to be written.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-k</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Deprecated in favor of -T KEY.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the default TTL to use for this key when it is converted
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys into a DNSKEY RR. If the key is imported into a zone,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys this is the TTL that will be used for it, unless there was
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys already a DNSKEY RRset in place, in which case the existing TTL
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys would take precedence. If this value is not set and there
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is no existing DNSKEY RRset, the TTL will default to the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys SOA TTL. Setting the default TTL to <code class="literal">0</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys or <code class="literal">none</code> is the same as leaving it unset.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the protocol value for the generated key. The protocol
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is a number between 0 and 255. The default is 3 (DNSSEC).
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Other possible values for this argument are listed in
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys RFC 2535 and its successors.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-q</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Quiet mode: Suppresses unnecessary output, including
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys progress indication. Without this option, when
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <span class="command"><strong>dnssec-keygen</strong></span> is run interactively
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys to generate an RSA or DSA key pair, it will print a string
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys of symbols to <code class="filename">stderr</code> indicating the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys progress of the key generation. A '.' indicates that a
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys random number has been found which passed an initial
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys sieve test; '+' means a number has passed a single
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys round of the Miller-Rabin primality test; a space
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys means that the number has passed all the tests and is
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys a satisfactory key.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the source of randomness. If the operating
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys system does not provide a <code class="filename">/dev/random</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys or equivalent device, the default source of randomness
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is keyboard input. <code class="filename">randomdev</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys specifies
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the name of a character device or file containing random
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys data to be used instead of the default. The special value
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <code class="filename">keyboard</code> indicates that keyboard
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys input should be used.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Create a new key which is an explicit successor to an
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys existing key. The name, algorithm, size, and type of the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys key will be set to match the existing key. The activation
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys date of the new key will be set to the inactivation date of
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the existing one. The publication date will be set to the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys activation date minus the prepublication interval, which
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys defaults to 30 days.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the strength value of the key. The strength is
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys a number between 0 and 15, and currently has no defined
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys purpose in DNSSEC.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-T <em class="replaceable"><code>rrtype</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Specifies the resource record type to use for the key.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys <code class="option">rrtype</code> must be either DNSKEY or KEY. The
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys default is DNSKEY when using a DNSSEC algorithm, but it can be
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys overridden to KEY for use with SIG(0).
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Using any TSIG algorithm (HMAC-* or DH) forces this option
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys to KEY.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Indicates the use of the key. <code class="option">type</code> must be
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is AUTHCONF. AUTH refers to the ability to authenticate
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys data, and CONF the ability to encrypt data.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the debugging level.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-V</span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Prints version information.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dl></div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refsection">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a name="id-1.14.10.9"></a><h2>TIMING OPTIONS</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If the argument begins with a '+' or '-', it is interpreted as
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys an offset from the present time. For convenience, if such an offset
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys then the offset is computed in years (defined as 365 24-hour days,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys ignoring leap years), months (defined as 30 24-hour days), weeks,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys days, hours, or minutes, respectively. Without a suffix, the offset
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys is computed in seconds. To explicitly prevent a date from being
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys set, use 'none' or 'never'.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="variablelist"><dl class="variablelist">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which a key is to be published to the zone.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys After that date, the key will be included in the zone but will
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys not be used to sign it. If not set, and if the -G option has
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys not been used, the default is "now".
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-P sync <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which CDS and CDNSKEY records that match this
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys key are to be published to the zone.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which the key is to be activated. After that
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys date, the key will be included in the zone and used to sign
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys it. If not set, and if the -G option has not been used, the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys default is "now". If set, if and -P is not set, then
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the publication date will be set to the activation date
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys minus the prepublication interval.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which the key is to be revoked. After that
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys date, the key will be flagged as revoked. It will be included
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys in the zone and will be used to sign it.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which the key is to be retired. After that
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys date, the key will still be included in the zone, but it
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys will not be used to sign it.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which the key is to be deleted. After that
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys date, the key will no longer be included in the zone. (It
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys may remain in the key repository, however.)
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-D sync <em class="replaceable"><code>date/offset</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd><p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the date on which the CDS and CDNSKEY records that match this
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys key are to be deleted.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys Sets the prepublication interval for a key. If set, then
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the publication and activation dates must be separated by at least
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll this much time. If the activation date is specified but the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys publication date isn't, then the publication date will default
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys to this much time before the activation date; conversely, if
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the publication date is specified but activation date isn't,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys then activation will be set to this much time after publication.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys If the key is being created as an explicit successor to another
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys key, then the default prepublication interval is 30 days;
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys otherwise it is zero.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys As with date offsets, if the argument is followed by one of
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys interval is measured in years, months, weeks, days, hours,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys or minutes, respectively. Without a suffix, the interval is
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys measured in seconds.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dd>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</dl></div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="refsection">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<a name="id-1.14.10.10"></a><h2>GENERATED KEYS</h2>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys When <span class="command"><strong>dnssec-keygen</strong></span> completes
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys successfully,
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys it prints a string of the form <code class="filename">Knnnn.+aaa+iiiii</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys to the standard output. This is an identification string for
56664548661c43ae04de4a32bce3510ed36aeaf9Wyllys Ingersoll the key it has generated.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<div class="itemizedlist"><ul class="itemizedlist" style="list-style-type: disc; ">
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<li class="listitem"><p><code class="filename">nnnn</code> is the key name.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></li>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<li class="listitem"><p><code class="filename">aaa</code> is the numeric representation
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys of the
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys algorithm.
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></li>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<li class="listitem"><p><code class="filename">iiiii</code> is the key identifier (or
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys footprint).
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys </p></li>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys</ul></div>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys<p><span class="command"><strong>dnssec-keygen</strong></span>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys creates two files, with names based
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys on the printed string. <code class="filename">Knnnn.+aaa+iiiii.key</code>
99ebb4ca412cb0a19d77a3899a87c055b9c30fa8wyllys contains the public key, and
<code class="filename">Knnnn.+aaa+iiiii.private</code> contains the
private
key.
</p>
<p>
The <code class="filename">.key</code> file contains a DNS KEY record
that
can be inserted into a zone file (directly or with a $INCLUDE
statement).
</p>
<p>
The <code class="filename">.private</code> file contains
algorithm-specific
fields. For obvious security reasons, this file does not have
general read permission.
</p>
<p>
Both <code class="filename">.key</code> and <code class="filename">.private</code>
files are generated for symmetric encryption algorithms such as
HMAC-MD5, even though the public and private key are equivalent.
</p>
</div>
<div class="refsection">
<a name="id-1.14.10.11"></a><h2>EXAMPLE</h2>
<p>
To generate a 768-bit DSA key for the domain
<strong class="userinput"><code>example.com</code></strong>, the following command would be
issued:
</p>
<p><strong class="userinput"><code>dnssec-keygen -a DSA -b 768 -n ZONE example.com</code></strong>
</p>
<p>
The command would print a string of the form:
</p>
<p><strong class="userinput"><code>Kexample.com.+003+26160</code></strong>
</p>
<p>
In this example, <span class="command"><strong>dnssec-keygen</strong></span> creates
the files <code class="filename">Kexample.com.+003+26160.key</code>
and
<code class="filename">Kexample.com.+003+26160.private</code>.
</p>
</div>
<div class="refsection">
<a name="id-1.14.10.12"></a><h2>SEE ALSO</h2>
<p><span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
<em class="citetitle">BIND 9 Administrator Reference Manual</em>,
<em class="citetitle">RFC 2539</em>,
<em class="citetitle">RFC 2845</em>,
<em class="citetitle">RFC 4034</em>.
</p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
</td>
</tr>
<tr>
<td width="40%" align="left" valign="top">
<span class="application">dnssec-keyfromlabel</span>�</td>
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top">�<span class="application">dnssec-revoke</span>
</td>
</tr>
</table>
</div>
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.0pre-alpha</p>
</body>
</html>