man.dnssec-keygen.html revision ef8014e56f35bb36daa5fd2c313f5e7963e97aa1
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
71cef386fae61275b03e203825680b39fedaa8c6Tinderbox User - Copyright (C) 2000-2003 Internet Software Consortium.
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - Permission to use, copy, modify, and/or distribute this software for any
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - purpose with or without fee is hereby granted, provided that the above
5347c0fcb04eaea19d9f39795646239f487c6207Tinderbox User - copyright notice and this permission notice appear in all copies.
d6fa26d0adaec6c910115be34fe7a5a5f402c14fMark Andrews - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
fd2597f75693a2279fdf588bd40dfe2407c42028Tinderbox User - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
cd32f419a8a5432fbb139f56ee73cbf68b9350ccTinderbox User - PERFORMANCE OF THIS SOFTWARE.
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<link rel="prev" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<link rel="next" href="man.dnssec-revoke.html" title="dnssec-revoke">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<table width="100%" summary="Navigation header">
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<tr><th colspan="3" align="center"><span class="application">dnssec-keygen</span></th></tr>
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<a accesskey="p" href="man.dnssec-keyfromlabel.html">Prev</a>�</td>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<th width="60%" align="center">Manual pages</th>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-revoke.html">Next</a>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<a name="man.dnssec-keygen"></a><div class="titlepage"></div>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<p><span class="application">dnssec-keygen</span> — DNSSEC key generation tool</p>
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater<div class="cmdsynopsis"><p><code class="command">dnssec-keygen</code> [<code class="option">-a <em class="replaceable"><code>algorithm</code></em></code>] [<code class="option">-b <em class="replaceable"><code>keysize</code></em></code>] [<code class="option">-n <em class="replaceable"><code>nametype</code></em></code>] [<code class="option">-3</code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-C</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f <em class="replaceable"><code>flag</code></em></code>] [<code class="option">-G</code>] [<code class="option">-g <em class="replaceable"><code>generator</code></em></code>] [<code class="option">-h</code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-k</code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-p <em class="replaceable"><code>protocol</code></em></code>] [<code class="option">-q</code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S <em class="replaceable"><code>key</code></em></code>] [<code class="option">-s <em class="replaceable"><code>strength</code></em></code>] [<code class="option">-t <em class="replaceable"><code>type</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-z</code>] {name}</p></div>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<p><span><strong class="command">dnssec-keygen</strong></span>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User generates keys for DNSSEC (Secure DNS), as defined in RFC 2535
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User and RFC 4034. It can also generate keys for use with
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User TSIG (Transaction Signatures) as defined in RFC 2845, or TKEY
7e71f05d8643aca84914437c900cb716444507e4Tinderbox User (Transaction Key) as defined in RFC 2930.
14a656f94b1fd0ababd84a772228dfa52276ba15Evan Hunt The <code class="option">name</code> of the key is specified on the command
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater line. For DNSSEC keys, this must match the name of the zone for
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater which the key is being generated.
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User Selects the cryptographic algorithm. For DNSSEC keys, the value
7911e6f9de303bca5a3d8b34f4330c8f7cecffaeTinderbox User of <code class="option">algorithm</code> must be one of RSAMD5, RSASHA1,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater DSA, NSEC3RSASHA1, NSEC3DSA, RSASHA256, RSASHA512, ECCGOST,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater ECDSAP256SHA256 or ECDSAP384SHA384.
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater be DH (Diffie Hellman), HMAC-MD5, HMAC-SHA1, HMAC-SHA224,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater HMAC-SHA256, HMAC-SHA384, or HMAC-SHA512. These values are
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater case insensitive.
10b865e9187fc77cae02f106ddcc9e03eecdfe06Tinderbox User If no algorithm is specified, then RSASHA1 will be used by
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater default, unless the <code class="option">-3</code> option is specified,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater in which case NSEC3RSASHA1 will be used instead. (If
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater <code class="option">-3</code> is used and an algorithm is specified,
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater that algorithm will be checked for compatibility with NSEC3.)
10b865e9187fc77cae02f106ddcc9e03eecdfe06Tinderbox User Note 1: that for DNSSEC, RSASHA1 is a mandatory to implement
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater algorithm, and DSA is recommended. For TSIG, HMAC-MD5 is
c313914d0e66b20969215e519bbf2ab4ecf39512Tinderbox User Note 2: DH, HMAC-MD5, and HMAC-SHA1 through HMAC-SHA512
fc2381b901eb162810f54a11cc512b95f55a60dfAutomatic Updater automatically set the -T KEY option.