man.dnssec-signzone.html revision bec154197d3d640b0d5b416cd5218ea58dca5d3a
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - Copyright (C) 2004-2013 Internet Systems Consortium, Inc. ("ISC")
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - Copyright (C) 2000-2003 Internet Software Consortium.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - Permission to use, copy, modify, and/or distribute this software for any
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - purpose with or without fee is hereby granted, provided that the above
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - copyright notice and this permission notice appear in all copies.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos - PERFORMANCE OF THIS SOFTWARE.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<link rel="prev" href="man.dnssec-settime.html" title="dnssec-settime">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<link rel="next" href="man.dnssec-verify.html" title="dnssec-verify">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
088fa5d9eaa83bf4b3d59a64c0519f42a143aaa9Alin Brici<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-verify.html">Next</a>
ba237d49c6ea085e3a01e2103494425558d042f6Alin Brici<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
ba237d49c6ea085e3a01e2103494425558d042f6Alin Brici<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-L <em class="replaceable"><code>serial</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-P</code>] [<code class="option">-p</code>] [<code class="option">-R</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-X <em class="replaceable"><code>extended end-time</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<p><span><strong class="command">dnssec-signzone</strong></span>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos signs a zone. It generates
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos NSEC and RRSIG records and produces a signed version of the
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos zone. The security status of delegations from the signed zone
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos (that is, whether the child zones are secure or not) is
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos determined by the presence or absence of a
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="filename">keyset</code> file for each child zone.
ebea1fb75b85aba5e3d6dd10e1949046a71e4a72Alin Brici Verify all generated signatures.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos Specifies the DNS class of the zone.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos Compatibility mode: Generate a
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos file in addition to
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos when signing a zone, for use by older versions of
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <span><strong class="command">dnssec-signzone</strong></span>.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos Look for <code class="filename">dsset-</code> or
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="filename">keyset-</code> files in <code class="option">directory</code>.
a1d206a2a22b5cde9b00633ea4472ae0b144d695Brendan Mmiller Output only those record types automatically managed by
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <span><strong class="command">dnssec-signzone</strong></span>, i.e. RRSIG, NSEC,
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos NSEC3 and NSEC3PARAM records. If smart signing
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos (<code class="option">-S</code>) is used, DNSKEY records are also
963cc96f97623aac2218f625e558cff1ddaea8c1Laszlo Hordos included. The resulting file can be included in the original
963cc96f97623aac2218f625e558cff1ddaea8c1Laszlo Hordos zone file with <span><strong class="command">$INCLUDE</strong></span>. This option
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos cannot be combined with <code class="option">-O raw</code>,
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="option">-O fast</code>, or serial number updating.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos Uses a crypto hardware (OpenSSL engine) for the crypto operations
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos it supports, for instance signing with private keys from
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos a secure key store. When compiled with PKCS#11 support
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos it defaults to pkcs11; the empty name resets it to no engine.
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos Generate DS records for child zones from
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
752de95b3096f209954edc85d0507259f156eabdLaszlo Hordos file. Existing DS records will be removed.
signatures on other records; e.g., when the private component
<span><strong class="command">"raw"</strong></span>, and <span><strong class="command">"fast"</strong></span>.
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
and <span><strong class="command">"fast"</strong></span>, <span><strong class="command">"raw"</strong></span>,
Kexample.com.+003+17247