man.dnssec-keygen.html revision eea6be913f9928255cab5f58ff27da41c1e8e23a
03831d35f7499c87d51205817c93e9a8d42c4baestevel - Copyright (C) 2004-2011 Internet Systems Consortium, Inc. ("ISC")
03831d35f7499c87d51205817c93e9a8d42c4baestevel - Copyright (C) 2000-2003 Internet Software Consortium.
03831d35f7499c87d51205817c93e9a8d42c4baestevel - Permission to use, copy, modify, and/or distribute this software for any
03831d35f7499c87d51205817c93e9a8d42c4baestevel - purpose with or without fee is hereby granted, provided that the above
03831d35f7499c87d51205817c93e9a8d42c4baestevel - copyright notice and this permission notice appear in all copies.
03831d35f7499c87d51205817c93e9a8d42c4baestevel - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
03831d35f7499c87d51205817c93e9a8d42c4baestevel - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
03831d35f7499c87d51205817c93e9a8d42c4baestevel - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
03831d35f7499c87d51205817c93e9a8d42c4baestevel - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
03831d35f7499c87d51205817c93e9a8d42c4baestevel - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
03831d35f7499c87d51205817c93e9a8d42c4baestevel - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
03831d35f7499c87d51205817c93e9a8d42c4baestevel - PERFORMANCE OF THIS SOFTWARE.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<!-- $Id: man.dnssec-keygen.html,v 1.198 2011/09/07 01:14:43 tbox Exp $ -->
03831d35f7499c87d51205817c93e9a8d42c4baestevel<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
03831d35f7499c87d51205817c93e9a8d42c4baestevel<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<p><span class="application">dnssec-keygen</span> — DNSSEC key generation tool</p>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e</code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {name}</p></div>
03831d35f7499c87d51205817c93e9a8d42c4baestevel<p><span><strong class="command">dnssec-keygen</strong></span>
03831d35f7499c87d51205817c93e9a8d42c4baestevel generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
03831d35f7499c87d51205817c93e9a8d42c4baestevel and RFC 4034. It can also generate keys for use with
03831d35f7499c87d51205817c93e9a8d42c4baestevel TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
03831d35f7499c87d51205817c93e9a8d42c4baestevel (Transaction Key) as defined in RFC 2930.
03831d35f7499c87d51205817c93e9a8d42c4baestevel The <code class="option">name</code> of the key is specified on the command
03831d35f7499c87d51205817c93e9a8d42c4baestevel line. For DNSSEC keys, this must match the name of the zone for
03831d35f7499c87d51205817c93e9a8d42c4baestevel which the key is being generated.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Selects the cryptographic algorithm. For DNSSEC keys, the value
03831d35f7499c87d51205817c93e9a8d42c4baestevel of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
03831d35f7499c87d51205817c93e9a8d42c4baestevel DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512 or ECCGOST.
03831d35f7499c87d51205817c93e9a8d42c4baestevel be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
03831d35f7499c87d51205817c93e9a8d42c4baestevel HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
03831d35f7499c87d51205817c93e9a8d42c4baestevel case insensitive.
03831d35f7499c87d51205817c93e9a8d42c4baestevel If no algorithm is specified, then RSASHA1 will be used by
03831d35f7499c87d51205817c93e9a8d42c4baestevel default, unless the <code class="option">-3</code> option is specified,
03831d35f7499c87d51205817c93e9a8d42c4baestevel in which case NSEC3RSASHA1 will be used instead. (If
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="option">-3</code> is used and an algorithm is specified,
03831d35f7499c87d51205817c93e9a8d42c4baestevel that algorithm will be checked for compatibility with NSEC3.)
03831d35f7499c87d51205817c93e9a8d42c4baestevel Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
03831d35f7499c87d51205817c93e9a8d42c4baestevel algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
03831d35f7499c87d51205817c93e9a8d42c4baestevel Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
03831d35f7499c87d51205817c93e9a8d42c4baestevel automatically set the -T KEY option.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-b <em class="replaceable"><code>keysize</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Specifies the number of bits in the key. The choice of key
03831d35f7499c87d51205817c93e9a8d42c4baestevel size depends on the algorithm used. RSA keys must be
03831d35f7499c87d51205817c93e9a8d42c4baestevel between 512 and 2048 bits. Diffie Hellman keys must be between
03831d35f7499c87d51205817c93e9a8d42c4baestevel 128 and 4096 bits. DSA keys must be between 512 and 1024
03831d35f7499c87d51205817c93e9a8d42c4baestevel bits and an exact multiple of 64. HMAC keys must be
03831d35f7499c87d51205817c93e9a8d42c4baestevel between 1 and 512 bits.
03831d35f7499c87d51205817c93e9a8d42c4baestevel The key size does not need to be specified if using a default
03831d35f7499c87d51205817c93e9a8d42c4baestevel algorithm. The default key size is 1024 bits for zone signing
03831d35f7499c87d51205817c93e9a8d42c4baestevel keys (ZSK's) and 2048 bits for key signing keys (KSK's,
03831d35f7499c87d51205817c93e9a8d42c4baestevel generated with <code class="option">-f KSK</code>). However, if an
03831d35f7499c87d51205817c93e9a8d42c4baestevel algorithm is explicitly specified with the <code class="option">-a</code>,
03831d35f7499c87d51205817c93e9a8d42c4baestevel then there is no default key size, and the <code class="option">-b</code>
03831d35f7499c87d51205817c93e9a8d42c4baestevel must be used.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-n <em class="replaceable"><code>nametype</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Specifies the owner type of the key. The value of
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="option">nametype</code> must either be ZONE (for a DNSSEC
03831d35f7499c87d51205817c93e9a8d42c4baestevel zone key (KEY/DNSKEY)), HOST or ENTITY (for a key associated with
03831d35f7499c87d51205817c93e9a8d42c4baestevel a host (KEY)),
03831d35f7499c87d51205817c93e9a8d42c4baestevel USER (for a key associated with a user(KEY)) or OTHER (DNSKEY).
03831d35f7499c87d51205817c93e9a8d42c4baestevel These values are case insensitive. Defaults to ZONE for DNSKEY
03831d35f7499c87d51205817c93e9a8d42c4baestevel generation.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Use an NSEC3-capable algorithm to generate a DNSSEC key.
03831d35f7499c87d51205817c93e9a8d42c4baestevel If this option is used and no algorithm is explicitly
03831d35f7499c87d51205817c93e9a8d42c4baestevel set on the command line, NSEC3RSASHA1 will be used by
03831d35f7499c87d51205817c93e9a8d42c4baestevel default. Note that RSASHA256, RSASHA512 and ECCGOST algorithms
03831d35f7499c87d51205817c93e9a8d42c4baestevel are NSEC3-capable.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Compatibility mode: generates an old-style key, without
03831d35f7499c87d51205817c93e9a8d42c4baestevel any metadata. By default, <span><strong class="command">dnssec-keygen</strong></span>
03831d35f7499c87d51205817c93e9a8d42c4baestevel will include the key's creation date in the metadata stored
03831d35f7499c87d51205817c93e9a8d42c4baestevel with the private key, and other dates may be set there as well
03831d35f7499c87d51205817c93e9a8d42c4baestevel (publication date, activation date, etc). Keys that include
03831d35f7499c87d51205817c93e9a8d42c4baestevel this data may be incompatible with older versions of BIND; the
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="option">-C</code> option suppresses them.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Indicates that the DNS record containing the key should have
03831d35f7499c87d51205817c93e9a8d42c4baestevel the specified class. If not specified, class IN is used.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Uses a crypto hardware (OpenSSL engine) for random number
03831d35f7499c87d51205817c93e9a8d42c4baestevel and, when supported, key generation. When compiled with PKCS#11
03831d35f7499c87d51205817c93e9a8d42c4baestevel support it defaults to pkcs11; the empty name resets it to
03831d35f7499c87d51205817c93e9a8d42c4baestevel If generating an RSAMD5/RSASHA1 key, use a large exponent.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-f <em class="replaceable"><code>flag</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Set the specified flag in the flag field of the KEY/DNSKEY record.
03831d35f7499c87d51205817c93e9a8d42c4baestevel The only recognized flags are KSK (Key Signing Key) and REVOKE.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Generate a key, but do not publish it or sign with it. This
03831d35f7499c87d51205817c93e9a8d42c4baestevel option is incompatible with -P and -A.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-g <em class="replaceable"><code>generator</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel If generating a Diffie Hellman key, use this generator.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Allowed values are 2 and 5. If no generator
03831d35f7499c87d51205817c93e9a8d42c4baestevel is specified, a known prime from RFC 2539 will be used
03831d35f7499c87d51205817c93e9a8d42c4baestevel if possible; otherwise the default is 2.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Prints a short summary of the options and arguments to
03831d35f7499c87d51205817c93e9a8d42c4baestevel <span><strong class="command">dnssec-keygen</strong></span>.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the directory in which the key files are to be written.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Deprecated in favor of -T KEY.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the default TTL to use for this key when it is converted
03831d35f7499c87d51205817c93e9a8d42c4baestevel into a DNSKEY RR. If the key is imported into a zone,
03831d35f7499c87d51205817c93e9a8d42c4baestevel this is the TTL that will be used for it, unless there was
03831d35f7499c87d51205817c93e9a8d42c4baestevel already a DNSKEY RRset in place, in which case the existing TTL
03831d35f7499c87d51205817c93e9a8d42c4baestevel would take precedence. Setting the default TTL to
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="literal">0</code> or <code class="literal">none</code> removes it.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-p <em class="replaceable"><code>protocol</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the protocol value for the generated key. The protocol
03831d35f7499c87d51205817c93e9a8d42c4baestevel is a number between 0 and 255. The default is 3 (DNSSEC).
03831d35f7499c87d51205817c93e9a8d42c4baestevel Other possible values for this argument are listed in
03831d35f7499c87d51205817c93e9a8d42c4baestevel RFC 2535 and its successors.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Quiet mode: Suppresses unnecessary output, including
03831d35f7499c87d51205817c93e9a8d42c4baestevel progress indication. Without this option, when
03831d35f7499c87d51205817c93e9a8d42c4baestevel <span><strong class="command">dnssec-keygen</strong></span> is run interactively
03831d35f7499c87d51205817c93e9a8d42c4baestevel to generate an RSA or DSA key pair, it will print a string
03831d35f7499c87d51205817c93e9a8d42c4baestevel of symbols to <code class="filename">stderr</code> indicating the
03831d35f7499c87d51205817c93e9a8d42c4baestevel progress of the key generation. A '.' indicates that a
03831d35f7499c87d51205817c93e9a8d42c4baestevel random number has been found which passed an initial
03831d35f7499c87d51205817c93e9a8d42c4baestevel sieve test; '+' means a number has passed a single
03831d35f7499c87d51205817c93e9a8d42c4baestevel round of the Miller-Rabin primality test; a space
03831d35f7499c87d51205817c93e9a8d42c4baestevel means that the number has passed all the tests and is
03831d35f7499c87d51205817c93e9a8d42c4baestevel a satisfactory key.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Specifies the source of randomness. If the operating
03831d35f7499c87d51205817c93e9a8d42c4baestevel system does not provide a <code class="filename">/dev/random</code>
03831d35f7499c87d51205817c93e9a8d42c4baestevel or equivalent device, the default source of randomness
03831d35f7499c87d51205817c93e9a8d42c4baestevel is keyboard input. <code class="filename">randomdev</code>
03831d35f7499c87d51205817c93e9a8d42c4baestevel the name of a character device or file containing random
03831d35f7499c87d51205817c93e9a8d42c4baestevel data to be used instead of the default. The special value
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="filename">keyboard</code> indicates that keyboard
03831d35f7499c87d51205817c93e9a8d42c4baestevel input should be used.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-S <em class="replaceable"><code>key</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Create a new key which is an explicit successor to an
03831d35f7499c87d51205817c93e9a8d42c4baestevel existing key. The name, algorithm, size, and type of the
03831d35f7499c87d51205817c93e9a8d42c4baestevel key will be set to match the existing key. The activation
03831d35f7499c87d51205817c93e9a8d42c4baestevel date of the new key will be set to the inactivation date of
03831d35f7499c87d51205817c93e9a8d42c4baestevel the existing one. The publication date will be set to the
03831d35f7499c87d51205817c93e9a8d42c4baestevel activation date minus the prepublication interval, which
03831d35f7499c87d51205817c93e9a8d42c4baestevel defaults to 30 days.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-s <em class="replaceable"><code>strength</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Specifies the strength value of the key. The strength is
03831d35f7499c87d51205817c93e9a8d42c4baestevel a number between 0 and 15, and currently has no defined
03831d35f7499c87d51205817c93e9a8d42c4baestevel purpose in DNSSEC.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-T <em class="replaceable"><code>rrtype</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Specifies the resource record type to use for the key.
03831d35f7499c87d51205817c93e9a8d42c4baestevel <code class="option">rrtype</code> must be either DNSKEY or KEY. The
03831d35f7499c87d51205817c93e9a8d42c4baestevel default is DNSKEY when using a DNSSEC algorithm, but it can be
03831d35f7499c87d51205817c93e9a8d42c4baestevel overridden to KEY for use with SIG(0).
03831d35f7499c87d51205817c93e9a8d42c4baestevel Using any TSIG algorithm (HMAC-* or DH) forces this option
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-t <em class="replaceable"><code>type</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Indicates the use of the key. <code class="option">type</code> must be
03831d35f7499c87d51205817c93e9a8d42c4baestevel one of AUTHCONF, NOAUTHCONF, NOAUTH, or NOCONF. The default
03831d35f7499c87d51205817c93e9a8d42c4baestevel is AUTHCONF. AUTH refers to the ability to authenticate
03831d35f7499c87d51205817c93e9a8d42c4baestevel data, and CONF the ability to encrypt data.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the debugging level.
03831d35f7499c87d51205817c93e9a8d42c4baestevel Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
03831d35f7499c87d51205817c93e9a8d42c4baestevel If the argument begins with a '+' or '-', it is interpreted as
03831d35f7499c87d51205817c93e9a8d42c4baestevel an offset from the present time. For convenience, if such an offset
03831d35f7499c87d51205817c93e9a8d42c4baestevel is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
03831d35f7499c87d51205817c93e9a8d42c4baestevel then the offset is computed in years (defined as 365 24-hour days,
03831d35f7499c87d51205817c93e9a8d42c4baestevel ignoring leap years), months (defined as 30 24-hour days), weeks,
03831d35f7499c87d51205817c93e9a8d42c4baestevel days, hours, or minutes, respectively. Without a suffix, the offset
03831d35f7499c87d51205817c93e9a8d42c4baestevel is computed in seconds.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the date on which a key is to be published to the zone.
03831d35f7499c87d51205817c93e9a8d42c4baestevel After that date, the key will be included in the zone but will
03831d35f7499c87d51205817c93e9a8d42c4baestevel not be used to sign it. If not set, and if the -G option has
03831d35f7499c87d51205817c93e9a8d42c4baestevel not been used, the default is "now".
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the date on which the key is to be activated. After that
03831d35f7499c87d51205817c93e9a8d42c4baestevel date, the key will be included in the zone and used to sign
03831d35f7499c87d51205817c93e9a8d42c4baestevel it. If not set, and if the -G option has not been used, the
03831d35f7499c87d51205817c93e9a8d42c4baestevel default is "now".
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the date on which the key is to be revoked. After that
03831d35f7499c87d51205817c93e9a8d42c4baestevel date, the key will be flagged as revoked. It will be included
03831d35f7499c87d51205817c93e9a8d42c4baestevel in the zone and will be used to sign it.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the date on which the key is to be retired. After that
03831d35f7499c87d51205817c93e9a8d42c4baestevel date, the key will still be included in the zone, but it
03831d35f7499c87d51205817c93e9a8d42c4baestevel will not be used to sign it.
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the date on which the key is to be deleted. After that
03831d35f7499c87d51205817c93e9a8d42c4baestevel date, the key will no longer be included in the zone. (It
03831d35f7499c87d51205817c93e9a8d42c4baestevel may remain in the key repository, however.)
03831d35f7499c87d51205817c93e9a8d42c4baestevel<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
03831d35f7499c87d51205817c93e9a8d42c4baestevel Sets the prepublication interval for a key. If set, then
03831d35f7499c87d51205817c93e9a8d42c4baestevel the publication and activation dates must be separated by at least
03831d35f7499c87d51205817c93e9a8d42c4baestevel this much time. If the activation date is specified but the