man.dnssec-settime.html revision f0aad5341752aefe5059832f6cf3abc3283c6e16
f86f2dc613a22ee06add9b878197922466df641bvboxsync<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<!--
f86f2dc613a22ee06add9b878197922466df641bvboxsync - Copyright (C) 2000-2016 Internet Systems Consortium, Inc. ("ISC")
f86f2dc613a22ee06add9b878197922466df641bvboxsync -
f86f2dc613a22ee06add9b878197922466df641bvboxsync - This Source Code Form is subject to the terms of the Mozilla Public
f86f2dc613a22ee06add9b878197922466df641bvboxsync - License, v. 2.0. If a copy of the MPL was not distributed with this
e64031e20c39650a7bc902a3e1aba613b9415deevboxsync - file, You can obtain one at http://mozilla.org/MPL/2.0/.
f86f2dc613a22ee06add9b878197922466df641bvboxsync-->
f86f2dc613a22ee06add9b878197922466df641bvboxsync<html lang="en">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<head>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<title>dnssec-settime</title>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<link rel="prev" href="man.dnssec-revoke.html" title="dnssec-revoke">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<link rel="next" href="man.dnssec-signzone.html" title="dnssec-signzone">
f86f2dc613a22ee06add9b878197922466df641bvboxsync</head>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="navheader">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<table width="100%" summary="Navigation header">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<tr><th colspan="3" align="center"><span class="application">dnssec-settime</span></th></tr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<tr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="20%" align="left">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<a accesskey="p" href="man.dnssec-revoke.html">Prev</a>�</td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<th width="60%" align="center">Manual pages</th>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-signzone.html">Next</a>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</tr>
2a047f0d7ee5964456dbc4dec9925031482588abvboxsync</table>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<hr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="refentry">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<a name="man.dnssec-settime"></a><div class="titlepage"></div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="refnamediv">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<h2>Name</h2>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<p><span class="application">dnssec-settime</span> &#8212; set the key timing metadata for a DNSSEC key</p>
8300beb17e7c288655895d07bfdc58a01f618218vboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="refsynopsisdiv">
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<h2>Synopsis</h2>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="cmdsynopsis"><p><code class="command">dnssec-settime</code> [<code class="option">-f</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-L <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-P <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-P sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-A <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-R <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-I <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-D sync <em class="replaceable"><code>date/offset</code></em></code>] [<code class="option">-h</code>] [<code class="option">-V</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] {keyfile}</p></div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</div>
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync<div class="refsection">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<a name="id-1.14.15.7"></a><h2>DESCRIPTION</h2>
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync<p><span class="command"><strong>dnssec-settime</strong></span>
f86f2dc613a22ee06add9b878197922466df641bvboxsync reads a DNSSEC private key file and sets the key timing metadata
f86f2dc613a22ee06add9b878197922466df641bvboxsync as specified by the <code class="option">-P</code>, <code class="option">-A</code>,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="option">-R</code>, <code class="option">-I</code>, and <code class="option">-D</code>
f86f2dc613a22ee06add9b878197922466df641bvboxsync options. The metadata can then be used by
f86f2dc613a22ee06add9b878197922466df641bvboxsync <span class="command"><strong>dnssec-signzone</strong></span> or other signing software to
f86f2dc613a22ee06add9b878197922466df641bvboxsync determine when a key is to be published, whether it should be
f86f2dc613a22ee06add9b878197922466df641bvboxsync used for signing a zone, etc.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync If none of these options is set on the command line,
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync then <span class="command"><strong>dnssec-settime</strong></span> simply prints the key timing
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync metadata already stored in the key.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync When key metadata fields are changed, both files of a key
f86f2dc613a22ee06add9b878197922466df641bvboxsync pair (<code class="filename">Knnnn.+aaa+iiiii.key</code> and
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="filename">Knnnn.+aaa+iiiii.private</code>) are regenerated.
f86f2dc613a22ee06add9b878197922466df641bvboxsync Metadata fields are stored in the private file. A human-readable
f86f2dc613a22ee06add9b878197922466df641bvboxsync description of the metadata is also placed in comments in the key
f86f2dc613a22ee06add9b878197922466df641bvboxsync file. The private file's permissions are always set to be
f86f2dc613a22ee06add9b878197922466df641bvboxsync inaccessible to anyone other than the owner (mode 0600).
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync</div>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<div class="refsection">
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<a name="id-1.14.15.8"></a><h2>OPTIONS</h2>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<div class="variablelist"><dl class="variablelist">
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-f</span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync Force an update of an old-format key with no metadata fields.
f86f2dc613a22ee06add9b878197922466df641bvboxsync Without this option, <span class="command"><strong>dnssec-settime</strong></span> will
f86f2dc613a22ee06add9b878197922466df641bvboxsync fail when attempting to update a legacy key. With this option,
f86f2dc613a22ee06add9b878197922466df641bvboxsync the key will be recreated in the new format, but with the
f86f2dc613a22ee06add9b878197922466df641bvboxsync original key data retained. The key's creation date will be
f86f2dc613a22ee06add9b878197922466df641bvboxsync set to the present time. If no other values are specified,
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync then the key's publication and activation dates will also
f86f2dc613a22ee06add9b878197922466df641bvboxsync be set to the present time.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dd><p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync Sets the directory in which the key files are to reside.
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync </p></dd>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<dt><span class="term">-L <em class="replaceable"><code>ttl</code></em></span></dt>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<dd><p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync Sets the default TTL to use for this key when it is converted
f86f2dc613a22ee06add9b878197922466df641bvboxsync into a DNSKEY RR. If the key is imported into a zone,
f86f2dc613a22ee06add9b878197922466df641bvboxsync this is the TTL that will be used for it, unless there was
f86f2dc613a22ee06add9b878197922466df641bvboxsync already a DNSKEY RRset in place, in which case the existing TTL
f86f2dc613a22ee06add9b878197922466df641bvboxsync would take precedence. If this value is not set and there
f86f2dc613a22ee06add9b878197922466df641bvboxsync is no existing DNSKEY RRset, the TTL will default to the
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync SOA TTL. Setting the default TTL to <code class="literal">0</code>
f86f2dc613a22ee06add9b878197922466df641bvboxsync or <code class="literal">none</code> removes it from the key.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dt><span class="term">-h</span></dt>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dd><p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync Emit usage message and exit.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dt><span class="term">-V</span></dt>
590bfe12ce22cd3716448fbb9f4dc51664bfe5e2vboxsync<dd><p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync Prints version information.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dd><p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync Sets the debugging level.
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync </p></dd>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<dd>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync Specifies the cryptographic hardware to use, when applicable.
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync </p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync When BIND is built with OpenSSL PKCS#11 support, this defaults
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync to the string "pkcs11", which identifies an OpenSSL engine
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync that can drive a cryptographic accelerator or hardware service
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync module. When BIND is built with native PKCS#11 cryptography
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync (--enable-native-pkcs11), it defaults to the path of the PKCS#11
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync provider library specified via "--with-pkcs11".
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync </p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync</dd>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync</dl></div>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync</div>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<div class="refsection">
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<a name="id-1.14.15.9"></a><h2>TIMING OPTIONS</h2>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<p>
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS.
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync If the argument begins with a '+' or '-', it is interpreted as
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync an offset from the present time. For convenience, if such an offset
f86f2dc613a22ee06add9b878197922466df641bvboxsync is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi',
f86f2dc613a22ee06add9b878197922466df641bvboxsync then the offset is computed in years (defined as 365 24-hour days,
f86f2dc613a22ee06add9b878197922466df641bvboxsync ignoring leap years), months (defined as 30 24-hour days), weeks,
f86f2dc613a22ee06add9b878197922466df641bvboxsync days, hours, or minutes, respectively. Without a suffix, the offset
f86f2dc613a22ee06add9b878197922466df641bvboxsync is computed in seconds. To unset a date, use 'none' or 'never'.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="variablelist"><dl class="variablelist">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dt><span class="term">-P <em class="replaceable"><code>date/offset</code></em></span></dt>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<dd><p>
72d7681289c829fb514dcc953c9b07ec4d20a28bvboxsync Sets the date on which a key is to be published to the zone.
f86f2dc613a22ee06add9b878197922466df641bvboxsync After that date, the key will be included in the zone but will
f86f2dc613a22ee06add9b878197922466df641bvboxsync not be used to sign it.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-P sync <em class="replaceable"><code>date/offset</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync Sets the date on which CDS and CDNSKEY records that match this
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync key are to be published to the zone.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p></dd>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<dt><span class="term">-A <em class="replaceable"><code>date/offset</code></em></span></dt>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<dd><p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync Sets the date on which the key is to be activated. After that
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync date, the key will be included in the zone and used to sign
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync it.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-R <em class="replaceable"><code>date/offset</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Sets the date on which the key is to be revoked. After that
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync date, the key will be flagged as revoked. It will be included
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync in the zone and will be used to sign it.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-I <em class="replaceable"><code>date/offset</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Sets the date on which the key is to be retired. After that
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync date, the key will still be included in the zone, but it
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync will not be used to sign it.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-D <em class="replaceable"><code>date/offset</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Sets the date on which the key is to be deleted. After that
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync date, the key will no longer be included in the zone. (It
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync may remain in the key repository, however.)
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-D sync <em class="replaceable"><code>date/offset</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Sets the date on which the CDS and CDNSKEY records that match this
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync key are to be deleted.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-S <em class="replaceable"><code>predecessor key</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Select a key for which the key being modified will be an
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync explicit successor. The name, algorithm, size, and type of the
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync predecessor key must exactly match those of the key being
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync modified. The activation date of the successor key will be set
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync to the inactivation date of the predecessor. The publication
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync date will be set to the activation date minus the prepublication
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync interval, which defaults to 30 days.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p></dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync Sets the prepublication interval for a key. If set, then
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync the publication and activation dates must be separated by at least
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync this much time. If the activation date is specified but the
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync publication date isn't, then the publication date will default
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync to this much time before the activation date; conversely, if
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync the publication date is specified but activation date isn't,
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync then activation will be set to this much time after publication.
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync </p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<p>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync If the key is being set to be an explicit successor to another
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync key, then the default prepublication interval is 30 days;
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync otherwise it is zero.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync As with date offsets, if the argument is followed by one of
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync interval is measured in years, months, weeks, days, hours,
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync or minutes, respectively. Without a suffix, the interval is
2f2587731657bec95ef807348711bccbae4b9c61vboxsync measured in seconds.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync</dd>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync</dl></div>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync</div>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<div class="refsection">
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<a name="id-1.14.15.10"></a><h2>PRINTING OPTIONS</h2>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync <span class="command"><strong>dnssec-settime</strong></span> can also be used to print the
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync timing metadata associated with a key.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<div class="variablelist"><dl class="variablelist">
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<dt><span class="term">-u</span></dt>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<dd><p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync Print times in UNIX epoch format.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p></dd>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync<dt><span class="term">-p <em class="replaceable"><code>C/P/Psync/A/R/I/D/Dsync/all</code></em></span></dt>
6af5a377dcdc4437fa51e183a5a8dad78abf2ec0vboxsync<dd><p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync Print a specific metadata value or set of metadata values.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync The <code class="option">-p</code> option may be followed by one or more
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync of the following letters or strings to indicate which value
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync or values to print:
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync <code class="option">C</code> for the creation date,
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync <code class="option">P</code> for the publication date,
83365ff77c1571f994b3a15bfbdee077d2ea8a07vboxsync <code class="option">Psync</code> for the CDS and CDNSKEY publication date,
83365ff77c1571f994b3a15bfbdee077d2ea8a07vboxsync <code class="option">A</code> for the activation date,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="option">R</code> for the revocation date,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="option">I</code> for the inactivation date,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="option">D</code> for the deletion date, and
f86f2dc613a22ee06add9b878197922466df641bvboxsync <code class="option">Dsync</code> for the CDS and CDNSKEY deletion date
f86f2dc613a22ee06add9b878197922466df641bvboxsync To print all of the metadata, use <code class="option">-p all</code>.
f86f2dc613a22ee06add9b878197922466df641bvboxsync </p></dd>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</dl></div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="refsection">
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync<a name="id-1.14.15.11"></a><h2>SEE ALSO</h2>
36ebaddfec017eee7e82ee466c25de002cdc4231vboxsync<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
36ec4b6f42e209d010ade084a96f46ce763345eavboxsync <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
f86f2dc613a22ee06add9b878197922466df641bvboxsync <em class="citetitle">RFC 5011</em>.
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync </p>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<div class="navfooter">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<hr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<table width="100%" summary="Navigation footer">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<tr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="40%" align="left">
334052e6de7b55199f6159fa6dfe5bf19591f12bvboxsync<a accesskey="p" href="man.dnssec-revoke.html">Prev</a>�</td>
72d7681289c829fb514dcc953c9b07ec4d20a28bvboxsync<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="40%" align="right">�<a accesskey="n" href="man.dnssec-signzone.html">Next</a>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</tr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<tr>
72d7681289c829fb514dcc953c9b07ec4d20a28bvboxsync<td width="40%" align="left" valign="top">
f86f2dc613a22ee06add9b878197922466df641bvboxsync<span class="application">dnssec-revoke</span>�</td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<td width="40%" align="right" valign="top">�<span class="application">dnssec-signzone</span>
22f8a6ac3bcf3e3c8aa1f275097d6f7ce392195bvboxsync</td>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</tr>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</table>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</div>
f86f2dc613a22ee06add9b878197922466df641bvboxsync<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.0</p>
f86f2dc613a22ee06add9b878197922466df641bvboxsync</body>
334052e6de7b55199f6159fa6dfe5bf19591f12bvboxsync</html>
f86f2dc613a22ee06add9b878197922466df641bvboxsync