man.dnssec-revoke.html revision de283bda6a902c2102a795192eeab3a769001c7d
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - Copyright (C) 2000-2003 Internet Software Consortium.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - Permission to use, copy, modify, and/or distribute this software for any
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - purpose with or without fee is hereby granted, provided that the above
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - copyright notice and this permission notice appear in all copies.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User - PERFORMANCE OF THIS SOFTWARE.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<link rel="prev" href="man.dnssec-keygen.html" title="dnssec-keygen">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<link rel="next" href="man.dnssec-settime.html" title="dnssec-settime">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<table width="100%" summary="Navigation header">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<tr><th colspan="3" align="center"><span class="application">dnssec-revoke</span></th></tr>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<th width="60%" align="center">Manual pages</th>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-settime.html">Next</a>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<a name="man.dnssec-revoke"></a><div class="titlepage"></div>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<p><span class="application">dnssec-revoke</span> — Set the REVOKED bit on a DNSSEC key</p>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<div class="cmdsynopsis"><p><code class="command">dnssec-revoke</code> [<code class="option">-hr</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-f</code>] [<code class="option">-R</code>] {keyfile}</p></div>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<p><span><strong class="command">dnssec-revoke</strong></span>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User reads a DNSSEC key file, sets the REVOKED bit on the key as defined
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User in RFC 5011, and creates a new pair of key files containing the
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User now-revoked key.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Emit usage message and exit.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Sets the directory in which the key files are to reside.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User After writing the new keyset files remove the original keyset
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Sets the debugging level.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Prints version information.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Specifies the cryptographic hardware to use, when applicable.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User When BIND is built with OpenSSL PKCS#11 support, this defaults
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User to the string "pkcs11", which identifies an OpenSSL engine
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User that can drive a cryptographic accelerator or hardware service
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User module. When BIND is built with native PKCS#11 cryptography
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User (--enable-native-pkcs11), it defaults to the path of the PKCS#11
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User provider library specified via "--with-pkcs11".
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Force overwrite: Causes <span><strong class="command">dnssec-revoke</strong></span> to
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User write the new key pair even if a file already exists matching
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User the algorithm and key ID of the revoked key.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User Print the key tag of the key with the REVOKE bit set but do
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User not revoke the key.
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<p><span class="corpauthor">Internet Systems Consortium</span>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<table width="100%" summary="Navigation footer">
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-settime.html">Next</a>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<span class="application">dnssec-keygen</span>�</td>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<td width="40%" align="right" valign="top">�<span class="application">dnssec-settime</span>
9a5087bf58f651bfff841192aba5afd06760d6ceTinderbox User<p style="text-align: center;">BIND 9.11.0pre-alpha</p>