man.dnssec-signzone.html revision 297be3708069ef31814d6d75c0d71a50a78feb03
885f47576842cf3c569315b9a48bd9f0ca03f203Automatic Updater - Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
71bd43eebd9d6e42dbcae62b730f5b6508d5acd8Automatic Updater - Copyright (C) 2000-2003 Internet Software Consortium.
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater - Permission to use, copy, modify, and distribute this software for any
2bb3422dc683c013db7042f5736240de6b86f182Automatic Updater - purpose with or without fee is hereby granted, provided that the above
7b67cfadd077feb0ec3e6c78385ba0d845a9789bMark Andrews - copyright notice and this permission notice appear in all copies.
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
bb93c8542756719b53096b9939e4041d0966026fAutomatic Updater - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
90ff38a0d8deaf5f9c2aa5916d99b2e572d28738Automatic Updater - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
ac4e70ff8955669341f435bc0a734a17c01af124Mark Andrews - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington - PERFORMANCE OF THIS SOFTWARE.
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater<!-- $Id: man.dnssec-signzone.html,v 1.60 2008/01/03 01:12:37 marka Exp $ -->
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
80faf1588895fd26490f82f95a7a1b771df1c324Automatic Updater<link rel="prev" href="man.dnssec-keygen.html" title="dnssec-keygen">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<link rel="next" href="man.named-checkconf.html" title="named-checkconf">
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson<table width="100%" summary="Navigation header">
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington<th width="60%" align="center">Manual pages</th>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<td width="20%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
3098364bcdd7a719fbafa5fc8d2cc9e90e5a5989Automatic Updater<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
ca904804e43f663f08eb1ac9d6d617930b9a3cd3Automatic Updater<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-t</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] {zonefile} [key...]</p></div>
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews<p><span><strong class="command">dnssec-signzone</strong></span>
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews signs a zone. It generates
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews NSEC and RRSIG records and produces a signed version of the
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson zone. The security status of delegations from the signed zone
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews (that is, whether the child zones are secure or not) is
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews determined by the presence or absence of a
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson <code class="filename">keyset</code> file for each child zone.
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont Verify all generated signatures.
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Specifies the DNS class of the zone.
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Treat specified key as a key signing key ignoring any
885f47576842cf3c569315b9a48bd9f0ca03f203Automatic Updater key flags. This option may be specified multiple times.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater Generate a DLV set in addition to the key (DNSKEY) and DS sets.
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews The domain is appended to the name of the records.
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater Look for <code class="filename">keyset</code> files in
fe80a4909bf62b602feaf246866e9d29f7654194Automatic Updater <code class="option">directory</code> as the directory
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson Generate DS records for child zones from keyset files.
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews Existing DS records will be removed.
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson Specify the date and time when the generated RRSIG records
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews become valid. This can be either an absolute or relative
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater time. An absolute start time is indicated by a number
19b3dc94bce93fa76bd7e066f9298630dbc9dcb4Automatic Updater in YYYYMMDDHHMMSS notation; 20000530144500 denotes
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater 14:45:00 UTC on May 30th, 2000. A relative start time is
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater indicated by +N, which is N seconds from the current time.
2bb3422dc683c013db7042f5736240de6b86f182Automatic Updater If no <code class="option">start-time</code> is specified, the current
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater time minus 1 hour (to allow for clock skew) is used.
3098364bcdd7a719fbafa5fc8d2cc9e90e5a5989Automatic Updater<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
d145b64cacc8d9cda51f9924ec70cd4661c3e2cfAutomatic Updater Specify the date and time when the generated RRSIG records
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater expire. As with <code class="option">start-time</code>, an absolute
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater time is indicated in YYYYMMDDHHMMSS notation. A time relative
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater to the start time is indicated with +N, which is N seconds from
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater the start time. A time relative to the current time is
5ae0e2c8b72fa44237edeb37d1945b1c3535ca39Automatic Updater indicated with now+N. If no <code class="option">end-time</code> is
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater specified, 30 days from the start time is used as a default.
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater The name of the output file containing the signed zone. The
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater default is to append <code class="filename">.signed</code> to
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater input filename.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Prints a short summary of the options and arguments to
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater <span><strong class="command">dnssec-signzone</strong></span>.
19b3dc94bce93fa76bd7e066f9298630dbc9dcb4Automatic Updater<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
7f94d9a8162c9a96b56e66176702b66e79d8e1a2Automatic Updater When a previously-signed zone is passed as input, records
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater may be resigned. The <code class="option">interval</code> option
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater specifies the cycle interval as an offset from the current
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater time (in seconds). If a RRSIG record expires after the
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater cycle interval, it is retained. Otherwise, it is considered
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater to be expiring soon, and it will be replaced.
7262eb86f2b465822206122921e2f357218f0cfdAutomatic Updater The default cycle interval is one quarter of the difference
96ea71632887c58a9d00f47eb318bf76b35903c3Mark Andrews between the signature end and start times. So if neither
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater <code class="option">end-time</code> or <code class="option">start-time</code>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater are specified, <span><strong class="command">dnssec-signzone</strong></span>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater signatures that are valid for 30 days, with a cycle
4cda4fd158d6ded5586bacea8c388445d99611eaAutomatic Updater interval of 7.5 days. Therefore, if any existing RRSIG records
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews are due to expire in less than 7.5 days, they would be
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews The format of the input zone file.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Possible formats are <span><strong class="command">"text"</strong></span> (default)
5ae0e2c8b72fa44237edeb37d1945b1c3535ca39Automatic Updater and <span><strong class="command">"raw"</strong></span>.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews This option is primarily intended to be used for dynamic
c5a53da13bb2126dcbbd5b45ca4904eccafe6621Automatic Updater signed zones so that the dumped zone file in a non-text
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews format containing updates can be signed directly.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater The use of this option does not make much sense for
bc0a53583d92309bebcf93c408e2f3247ebd3d3cAutomatic Updater non-dynamic zones.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater When signing a zone with a fixed signature lifetime, all
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington RRSIG records issued at the time of signing expires
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater simultaneously. If the zone is incrementally signed, i.e.
7eda3642eea03f1181e41540c7c8791a57759383Automatic Updater a previously-signed zone is passed as input to the signer,
96713299d08c0735c18ebe8772dd2cc1ecd4356aAutomatic Updater all expired signatures have to be regenerated at about the
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater same time. The <code class="option">jitter</code> option specifies a
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater jitter window that will be used to randomize the signature
7eda3642eea03f1181e41540c7c8791a57759383Automatic Updater expire time, thus spreading incremental signature
00be0f9f61d4c6bf197d000bfa1a6b7e70ea0866Automatic Updater regeneration over time.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Signature lifetime jitter also to some extent benefits
5c0fc20d6e59216d9a142409e5fdb498153aeaa5Automatic Updater validators and servers by spreading out cache expiration,
71bd43eebd9d6e42dbcae62b730f5b6508d5acd8Automatic Updater i.e. if large numbers of RRSIGs don't expire at the same time
0ce87e5749aabb8eef1e0a37e4bd6e6ffa1d7196Automatic Updater from all caches there will be less congestion than if all
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington validators need to refetch at mostly the same time.
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Specifies the number of threads to use. By default, one
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews thread is started for each detected CPU.
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater The SOA serial number format of the signed zone.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Possible formats are <span><strong class="command">"keep"</strong></span> (default),
3c5dffc581c882235485cf5eaf7cd6a5e07548bfAutomatic Updater <span><strong class="command">"increment"</strong></span> and
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews <span><strong class="command">"unixtime"</strong></span>.
59528addd704f8d5757b54e540520f74e588a7c7Automatic Updater<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dd><p>Do not modify the SOA serial number.</p></dd>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews<dd><p>Increment the SOA serial number using RFC 1982
4b2cb1422c7c600fbc13b1cb06a8b4693bc11af8Mark Andrews<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<dd><p>Set the SOA serial number to the number of seconds
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews The zone origin. If not specified, the name of the zone file
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson is assumed to be the origin.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson The format of the output file containing the signed zone.
aa1d397c4736cd86540555193d71e55fa3b37b2aMark Andrews Possible formats are <span><strong class="command">"text"</strong></span> (default)
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews and <span><strong class="command">"raw"</strong></span>.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Use pseudo-random data when signing the zone. This is faster,
b4cebdb6ccde66a8f3e397a1b90b0cf788519d69Automatic Updater but less secure, than using real random data. This option
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater may be useful when signing large zones or when the entropy
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater source is limited.
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater Specifies the source of randomness. If the operating
bc0a4c01beede169df81a3ee5b614ed9e82339dbAutomatic Updater system does not provide a <code class="filename">/dev/random</code>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington or equivalent device, the default source of randomness
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater is keyboard input. <code class="filename">randomdev</code>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the name of a character device or file containing random
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington data to be used instead of the default. The special value
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <code class="filename">keyboard</code> indicates that keyboard
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington input should be used.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Print statistics at completion.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Sets the debugging level.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Ignore KSK flag on key when determining what to sign.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington The file containing the zone to be signed.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington Specify which keys should be used to sign the zone. If
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington no keys are specified, then the zone will be examined
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington for DNSKEY records at the zone apex. If these are found and
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington there are matching private keys, in the current directory,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington then these will be used for signing.
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington The following command signs the <strong class="userinput"><code>example.com</code></strong>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington (Kexample.com.+003+17247). The zone's keys must be in the master
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington file (<code class="filename">db.example.com</code>). This invocation looks
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington for <code class="filename">keyset</code> files, in the current directory,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington so that DS records can be generated from them (<span><strong class="command">-g</strong></span>).
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington the file <code class="filename">db.example.com.signed</code>. This
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington file should be referenced in a zone statement in a
a26b22914b7bf25f065afb8cdef983766dcd672bAutomatic Updater <code class="filename">named.conf</code> file.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington This example re-signs a previously signed zone with default parameters.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington The private keys are assumed to be in the current directory.
d4ef65050feac78554addf6e16a06c6e2e0bd331Brian Wellington<pre class="programlisting">% cp db.example.com.signed db.example.com
998b76837ac21e4243a0f97618ea91206be8c028Automatic Updater<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington<p><span class="corpauthor">Internet Systems Consortium</span>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<table width="100%" summary="Navigation footer">
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
c01dec514a81ecf8c17ca3ef8c3ba95e437295ebAutomatic Updater<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
7af91d15b2ce1ce32f7320f6d5cc3b83621c241aAutomatic Updater<td width="40%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<span class="application">dnssec-keygen</span>�</td>
ce9cad6bb04869c5e94d9dc721032b25117f9210Automatic Updater<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
9e3a7b0faf417a10f5f689edf288807b2d5eedc5Brian Wellington<td width="40%" align="right" valign="top">�<span class="application">named-checkconf</span>