man.dnssec-settime.html revision ad8f23aed6c75f94f238c1f23f4e17515d28eb55
843e19887f64dde75055cf8842fc4db2171eff45johnlev - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
843e19887f64dde75055cf8842fc4db2171eff45johnlev - Copyright (C) 2000-2003 Internet Software Consortium.
843e19887f64dde75055cf8842fc4db2171eff45johnlev - Permission to use, copy, modify, and/or distribute this software for any
843e19887f64dde75055cf8842fc4db2171eff45johnlev - purpose with or without fee is hereby granted, provided that the above
843e19887f64dde75055cf8842fc4db2171eff45johnlev - copyright notice and this permission notice appear in all copies.
843e19887f64dde75055cf8842fc4db2171eff45johnlev - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
843e19887f64dde75055cf8842fc4db2171eff45johnlev - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
843e19887f64dde75055cf8842fc4db2171eff45johnlev - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
843e19887f64dde75055cf8842fc4db2171eff45johnlev - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
843e19887f64dde75055cf8842fc4db2171eff45johnlev - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
843e19887f64dde75055cf8842fc4db2171eff45johnlev - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
843e19887f64dde75055cf8842fc4db2171eff45johnlev - PERFORMANCE OF THIS SOFTWARE.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<!-- $Id$ -->
843e19887f64dde75055cf8842fc4db2171eff45johnlev<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<link rel="prev" href="man.dnssec-revoke.html" title="dnssec-revoke">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<link rel="next" href="man.dnssec-signzone.html" title="dnssec-signzone">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
843e19887f64dde75055cf8842fc4db2171eff45johnlev<tr><th colspan="3" align="center"><span class="application">dnssec-settime</span></th></tr>
843e19887f64dde75055cf8842fc4db2171eff45johnlev<a accesskey="p" href="man.dnssec-revoke.html">Prev</a>�</td>
843e19887f64dde75055cf8842fc4db2171eff45johnlev<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-signzone.html">Next</a>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab<a name="man.dnssec-settime"></a><div class="titlepage"></div>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab<p><span class="application">dnssec-settime</span> — Set the key timing metadata for a DNSSEC key</p>
843e19887f64dde75055cf8842fc4db2171eff45johnlev<div class="cmdsynopsis"><p><code class="command">dnssec-settime</code> [<code class="option">-f</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-V</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] {keyfile}</p></div>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab<p><span><strong class="command">dnssec-settime</strong></span>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab reads a DNSSEC private key file and sets the key timing metadata
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab as specified by the <code class="option">-P</code>, <code class="option">-A</code>,
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="option">-R</code>, <code class="option">-I</code>, and <code class="option">-D</code>
843e19887f64dde75055cf8842fc4db2171eff45johnlev options. The metadata can then be used by
843e19887f64dde75055cf8842fc4db2171eff45johnlev <span><strong class="command">dnssec-signzone</strong></span> or other signing software to
843e19887f64dde75055cf8842fc4db2171eff45johnlev determine when a key is to be published, whether it should be
843e19887f64dde75055cf8842fc4db2171eff45johnlev used for signing a zone, etc.
843e19887f64dde75055cf8842fc4db2171eff45johnlev If none of these options is set on the command line,
843e19887f64dde75055cf8842fc4db2171eff45johnlev then <span><strong class="command">dnssec-settime</strong></span> simply prints the key timing
843e19887f64dde75055cf8842fc4db2171eff45johnlev metadata already stored in the key.
843e19887f64dde75055cf8842fc4db2171eff45johnlev When key metadata fields are changed, both files of a key
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
843e19887f64dde75055cf8842fc4db2171eff45johnlev Metadata fields are stored in the private file. A human-readable
843e19887f64dde75055cf8842fc4db2171eff45johnlev description of the metadata is also placed in comments in the key
843e19887f64dde75055cf8842fc4db2171eff45johnlev file. The private file's permissions are always set to be
843e19887f64dde75055cf8842fc4db2171eff45johnlev inaccessible to anyone other than the owner (mode 0600).
843e19887f64dde75055cf8842fc4db2171eff45johnlev Force an update of an old-format key with no metadata fields.
843e19887f64dde75055cf8842fc4db2171eff45johnlev Without this option, <span><strong class="command">dnssec-settime</strong></span> will
843e19887f64dde75055cf8842fc4db2171eff45johnlev fail when attempting to update a legacy key. With this option,
843e19887f64dde75055cf8842fc4db2171eff45johnlev the key will be recreated in the new format, but with the
843e19887f64dde75055cf8842fc4db2171eff45johnlev original key data retained. The key's creation date will be
843e19887f64dde75055cf8842fc4db2171eff45johnlev set to the present time. If no other values are specified,
843e19887f64dde75055cf8842fc4db2171eff45johnlev then the key's publication and activation dates will also
843e19887f64dde75055cf8842fc4db2171eff45johnlev be set to the present time.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the directory in which the key files are to reside.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the default TTL to use for this key when it is converted
843e19887f64dde75055cf8842fc4db2171eff45johnlev into a DNSKEY RR. If the key is imported into a zone,
843e19887f64dde75055cf8842fc4db2171eff45johnlev this is the TTL that will be used for it, unless there was
843e19887f64dde75055cf8842fc4db2171eff45johnlev already a DNSKEY RRset in place, in which case the existing TTL
843e19887f64dde75055cf8842fc4db2171eff45johnlev would take precedence. If this value is not set and there
843e19887f64dde75055cf8842fc4db2171eff45johnlev is no existing DNSKEY RRset, the TTL will default to the
843e19887f64dde75055cf8842fc4db2171eff45johnlev SOA TTL. Setting the default TTL to <code class="literal">0</code>
843e19887f64dde75055cf8842fc4db2171eff45johnlev or <code class="literal">none</code> removes it from the key.
843e19887f64dde75055cf8842fc4db2171eff45johnlev Emit usage message and exit.
843e19887f64dde75055cf8842fc4db2171eff45johnlev Prints version information.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the debugging level.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Specifies the cryptographic hardware to use, when applicable.
843e19887f64dde75055cf8842fc4db2171eff45johnlev When BIND is built with OpenSSL PKCS#11 support, this defaults
843e19887f64dde75055cf8842fc4db2171eff45johnlev to the string "pkcs11", which identifies an OpenSSL engine
843e19887f64dde75055cf8842fc4db2171eff45johnlev that can drive a cryptographic accelerator or hardware service
843e19887f64dde75055cf8842fc4db2171eff45johnlev module. When BIND is built with native PKCS#11 cryptography
843e19887f64dde75055cf8842fc4db2171eff45johnlev (--enable-native-pkcs11), it defaults to the path of the PKCS#11
843e19887f64dde75055cf8842fc4db2171eff45johnlev provider library specified via "--with-pkcs11".
843e19887f64dde75055cf8842fc4db2171eff45johnlev Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
843e19887f64dde75055cf8842fc4db2171eff45johnlev If the argument begins with a '+' or '-', it is interpreted as
843e19887f64dde75055cf8842fc4db2171eff45johnlev an offset from the present time. For convenience, if such an offset
843e19887f64dde75055cf8842fc4db2171eff45johnlev is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
843e19887f64dde75055cf8842fc4db2171eff45johnlev then the offset is computed in years (defined as 365 24-hour days,
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab ignoring leap years), months (defined as 30 24-hour days), weeks,
843e19887f64dde75055cf8842fc4db2171eff45johnlev days, hours, or minutes, respectively. Without a suffix, the offset
843e19887f64dde75055cf8842fc4db2171eff45johnlev is computed in seconds. To unset a date, use 'none' or 'never'.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the date on which a key is to be published to the zone.
843e19887f64dde75055cf8842fc4db2171eff45johnlev After that date, the key will be included in the zone but will
843e19887f64dde75055cf8842fc4db2171eff45johnlev not be used to sign it.
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab Sets the date on which the key is to be activated. After that
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab date, the key will be included in the zone and used to sign
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab Sets the date on which the key is to be revoked. After that
843e19887f64dde75055cf8842fc4db2171eff45johnlev date, the key will be flagged as revoked. It will be included
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab in the zone and will be used to sign it.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the date on which the key is to be retired. After that
843e19887f64dde75055cf8842fc4db2171eff45johnlev date, the key will still be included in the zone, but it
843e19887f64dde75055cf8842fc4db2171eff45johnlev will not be used to sign it.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the date on which the key is to be deleted. After that
843e19887f64dde75055cf8842fc4db2171eff45johnlev date, the key will no longer be included in the zone. (It
843e19887f64dde75055cf8842fc4db2171eff45johnlev may remain in the key repository, however.)
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-S <em class="replaceable"><code>predecessor key</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Select a key for which the key being modified will be an
843e19887f64dde75055cf8842fc4db2171eff45johnlev explicit successor. The name, algorithm, size, and type of the
843e19887f64dde75055cf8842fc4db2171eff45johnlev predecessor key must exactly match those of the key being
843e19887f64dde75055cf8842fc4db2171eff45johnlev modified. The activation date of the successor key will be set
843e19887f64dde75055cf8842fc4db2171eff45johnlev to the inactivation date of the predecessor. The publication
843e19887f64dde75055cf8842fc4db2171eff45johnlev date will be set to the activation date minus the prepublication
843e19887f64dde75055cf8842fc4db2171eff45johnlev interval, which defaults to 30 days.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Sets the prepublication interval for a key. If set, then
843e19887f64dde75055cf8842fc4db2171eff45johnlev the publication and activation dates must be separated by at least
843e19887f64dde75055cf8842fc4db2171eff45johnlev this much time. If the activation date is specified but the
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab publication date isn't, then the publication date will default
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab to this much time before the activation date; conversely, if
843e19887f64dde75055cf8842fc4db2171eff45johnlev the publication date is specified but activation date isn't,
843e19887f64dde75055cf8842fc4db2171eff45johnlev then activation will be set to this much time after publication.
843e19887f64dde75055cf8842fc4db2171eff45johnlev If the key is being set to be an explicit successor to another
843e19887f64dde75055cf8842fc4db2171eff45johnlev key, then the default prepublication interval is 30 days;
843e19887f64dde75055cf8842fc4db2171eff45johnlev otherwise it is zero.
843e19887f64dde75055cf8842fc4db2171eff45johnlev As with date offsets, if the argument is followed by one of
843e19887f64dde75055cf8842fc4db2171eff45johnlev the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
a576ab5b6e08c47732b3dedca9eaa8a8cbb85720rab interval is measured in years, months, weeks, days, hours,
843e19887f64dde75055cf8842fc4db2171eff45johnlev or minutes, respectively. Without a suffix, the interval is
843e19887f64dde75055cf8842fc4db2171eff45johnlev measured in seconds.
843e19887f64dde75055cf8842fc4db2171eff45johnlev <span><strong class="command">dnssec-settime</strong></span> can also be used to print the
843e19887f64dde75055cf8842fc4db2171eff45johnlev timing metadata associated with a key.
843e19887f64dde75055cf8842fc4db2171eff45johnlev Print times in UNIX epoch format.
843e19887f64dde75055cf8842fc4db2171eff45johnlev<dt><span class="term">-p <em class="replaceable"><code>C/P/A/R/I/D/all</code></em></span></dt>
843e19887f64dde75055cf8842fc4db2171eff45johnlev Print a specific metadata value or set of metadata values.
843e19887f64dde75055cf8842fc4db2171eff45johnlev The <code class="option">-p</code> option may be followed by one or more
843e19887f64dde75055cf8842fc4db2171eff45johnlev of the following letters to indicate which value or values to print:
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="option">C</code> for the creation date,
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="option">P</code> for the publication date,
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="option">A</code> for the activation date,
843e19887f64dde75055cf8842fc4db2171eff45johnlev <code class="option">R</code> for the revocation date,