man.dnssec-revoke.html revision c80e152862cc3e3207dc837fde7116bd4c0e4b9d
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen - Copyright (C) 2000-2018 Internet Systems Consortium, Inc. ("ISC")
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen - This Source Code Form is subject to the terms of the Mozilla Public
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen - License, v. 2.0. If a copy of the MPL was not distributed with this
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen - file, You can obtain one at http://mozilla.org/MPL/2.0/.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<link rel="prev" href="man.dnssec-keymgr.html" title="dnssec-keymgr">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<link rel="next" href="man.dnssec-settime.html" title="dnssec-settime">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<table width="100%" summary="Navigation header">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<tr><th colspan="3" align="center"><span class="application">dnssec-revoke</span></th></tr>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<a accesskey="p" href="man.dnssec-keymgr.html">Prev</a>�</td>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<th width="60%" align="center">Manual pages</th>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-settime.html">Next</a>
f1d5b66c20fc9cf79e5e407874f0385b58f697faapenner<a name="man.dnssec-revoke"></a><div class="titlepage"></div>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen <span class="application">dnssec-revoke</span>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen — set the REVOKED bit on a DNSSEC key
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen [<code class="option">-v <em class="replaceable"><code>level</code></em></code>]
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>]
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>]
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen <p><span class="command"><strong>dnssec-revoke</strong></span>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen reads a DNSSEC key file, sets the REVOKED bit on the key as defined
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen in RFC 5011, and creates a new pair of key files containing the
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen now-revoked key.
c930c9327ee379ea94e4310795d52f9f8da679dcKrzysztof Kosiński<a name="id-1.14.14.8"></a><h2>OPTIONS</h2>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen <div class="variablelist"><dl class="variablelist">
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Emit usage message and exit.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Sets the directory in which the key files are to reside.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen After writing the new keyset files remove the original keyset
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Sets the debugging level.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Prints version information.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Specifies the cryptographic hardware to use, when applicable.
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen When BIND is built with OpenSSL PKCS#11 support, this defaults
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen to the string "pkcs11", which identifies an OpenSSL engine
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen that can drive a cryptographic accelerator or hardware service
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen module. When BIND is built with native PKCS#11 cryptography
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen (--enable-native-pkcs11), it defaults to the path of the PKCS#11
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen provider library specified via "--with-pkcs11".
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen Force overwrite: Causes <span class="command"><strong>dnssec-revoke</strong></span> to
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen write the new key pair even if a file already exists matching
3a19eef6d6d857df2a0420f72179887b42f9b77eJohan B. C. Engelen the algorithm and key ID of the revoked key.
<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.3rc2 (Extended Support Version)</p>