man.dnssec-signzone.html revision 07e2d9518d5d78818b469de77f398f3439106abf
80833bb9a1bf25dcf19e814438a4b311d2e1f4cffuankg - Copyright (C) 2004-2008 Internet Systems Consortium, Inc. ("ISC")
a34684a59b60a4173c25035d0c627ef17e6dc215rpluem - Copyright (C) 2000-2003 Internet Software Consortium.
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - Permission to use, copy, modify, and distribute this software for any
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - purpose with or without fee is hereby granted, provided that the above
1337c7673efc1f80f634139fbad7cbb98a0dc657ylavic - copyright notice and this permission notice appear in all copies.
4da61833a1cbbca94094f9653fd970582b97a72etrawick - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
4da61833a1cbbca94094f9653fd970582b97a72etrawick - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
4da61833a1cbbca94094f9653fd970582b97a72etrawick - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
4da61833a1cbbca94094f9653fd970582b97a72etrawick - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
4789804be088bcd86ae637a29cdb7fda25169521jailletc - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
4789804be088bcd86ae637a29cdb7fda25169521jailletc - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
4789804be088bcd86ae637a29cdb7fda25169521jailletc - PERFORMANCE OF THIS SOFTWARE.
e50c3026198fd496f183cda4c32a202925476778covener<!-- $Id: man.dnssec-signzone.html,v 1.95 2008/12/01 01:11:34 tbox Exp $ -->
5b88c8507d5ef6d0c4cfbc78230294968175b638minfrin<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
6c3b9cebb551140fbb25d58bae08b539b3802133ylavic<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
4f29b65ab4b547ad5dbe506e2d0ff5d12ead9247ylavic<link rel="prev" href="man.dnssec-keygen.html" title="dnssec-keygen">
4f29b65ab4b547ad5dbe506e2d0ff5d12ead9247ylavic<link rel="next" href="man.named-checkconf.html" title="named-checkconf">
0a0df13b7f1f4f1a74fe295253d89ca3911b301aylavic<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
69301145375a889e7e37caf7cc7321ac0f91801erpluem<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
506bfe33206b2fece40ef25f695af39dd4130facjkaluza<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
506bfe33206b2fece40ef25f695af39dd4130facjkaluza<td width="20%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
2e6f4d654c96c98b761fb012fd25c5d5b1558c44sf<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
17e6c95f3b22d18acdf8380fb26a8d0e10c80767ylavic<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
e8bd80a4bb88199d2f9a24a50345688e52d9c116ylavic<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-t</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic<p><span><strong class="command">dnssec-signzone</strong></span>
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic signs a zone. It generates
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic NSEC and RRSIG records and produces a signed version of the
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic zone. The security status of delegations from the signed zone
330e16bea8fe9cace4de90c349750c03dfb1fe64ylavic (that is, whether the child zones are secure or not) is
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener determined by the presence or absence of a
d7205b1a86c51c27b71a2c458dc453fd53a261c1covener <code class="filename">keyset</code> file for each child zone.
5d1ba75b8794925e67591c209085a49279791de9covener Verify all generated signatures.
5d1ba75b8794925e67591c209085a49279791de9covener<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand Specifies the DNS class of the zone.
032982212dbcc7c3cce95bf89c503bb56e185ac7kbrand<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
caad2986f81ab263f7af41467dd622dc9add17f3ylavic Treat specified key as a key signing key ignoring any
caad2986f81ab263f7af41467dd622dc9add17f3ylavic key flags. This option may be specified multiple times.
45a10d38e6051fd7bdf9d742aaae633d97ff02abjailletc<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
f7317ff316c2b141feea31bddb74d5d3fa1584edjorton Generate a DLV set in addition to the key (DNSKEY) and DS sets.
2165214331e4afafca4048f66f303d0253d7b001covener The domain is appended to the name of the records.
a34684a59b60a4173c25035d0c627ef17e6dc215rpluem<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
1e2d421a36999d292042a5539971070d54aa6c63ylavic Look for <code class="filename">keyset</code> files in
1e2d421a36999d292042a5539971070d54aa6c63ylavic <code class="option">directory</code> as the directory
0b67eb8568cd58bb77082703951679b42cf098actrawick Generate DS records for child zones from keyset files.
0b67eb8568cd58bb77082703951679b42cf098actrawick Existing DS records will be removed.
0b67eb8568cd58bb77082703951679b42cf098actrawick<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
fb1985a97912b25ec6564c73e610a31e5fc6e25fcovener Specify the date and time when the generated RRSIG records
09c87c777bed1655621bb20e1c46cb6b1a63279dcovener become valid. This can be either an absolute or relative
6502b7b32f980cc2093bb3ebce37e5e4dc68fba4ylavic time. An absolute start time is indicated by a number
6502b7b32f980cc2093bb3ebce37e5e4dc68fba4ylavic in YYYYMMDDHHMMSS notation; 20000530144500 denotes
3060ce7f798fbda7999cd4ddf89b525d2b294185covener 14:45:00 UTC on May 30th, 2000. A relative start time is
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic indicated by +N, which is N seconds from the current time.
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic If no <code class="option">start-time</code> is specified, the current
c1a63b8fad09c419c1a64f75993feb8a343a6801ylavic time minus 1 hour (to allow for clock skew) is used.
e6b4bd1113567627ab6bb6c6a7105e1e01a7d889jailletc<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
e466c40e1801982602ee0200c9e8b61cc148742djailletc Specify the date and time when the generated RRSIG records
457468b82e59d01eba00dd9d0817309c8f5e414ejim expire. As with <code class="option">start-time</code>, an absolute
457468b82e59d01eba00dd9d0817309c8f5e414ejim time is indicated in YYYYMMDDHHMMSS notation. A time relative
457468b82e59d01eba00dd9d0817309c8f5e414ejim to the start time is indicated with +N, which is N seconds from
04983e3bd1754764eec7d6bb772fe3b0bf391771jorton the start time. A time relative to the current time is
04983e3bd1754764eec7d6bb772fe3b0bf391771jorton indicated with now+N. If no <code class="option">end-time</code> is
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem specified, 30 days from the start time is used as a default.
15660979a30d251681463de2e0584853890082accovener<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
49dacedb6c387b786b7911082ff35121a45f414bcovener The name of the output file containing the signed zone. The
cfd9415521847b2f9394fad04fb701cfb955f503rjung default is to append <code class="filename">.signed</code> to
cfd9415521847b2f9394fad04fb701cfb955f503rjung input filename.
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe Prints a short summary of the options and arguments to
28c31fb73c1264bd1d0ff932573677030b024c7dwrowe <span><strong class="command">dnssec-signzone</strong></span>.
63b9f1f5880391261705f696d7d65507bbe9ace3covener<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
49dacedb6c387b786b7911082ff35121a45f414bcovener When a previously-signed zone is passed as input, records
49dacedb6c387b786b7911082ff35121a45f414bcovener may be resigned. The <code class="option">interval</code> option
49dacedb6c387b786b7911082ff35121a45f414bcovener specifies the cycle interval as an offset from the current
49dacedb6c387b786b7911082ff35121a45f414bcovener time (in seconds). If a RRSIG record expires after the
3c990331fc6702119e4f5b8ba9eae3021aea5265jim cycle interval, it is retained. Otherwise, it is considered
3c990331fc6702119e4f5b8ba9eae3021aea5265jim to be expiring soon, and it will be replaced.
fc42512879dd0504532f52fe5d0d0383dda96a1eniq The default cycle interval is one quarter of the difference
fc42512879dd0504532f52fe5d0d0383dda96a1eniq between the signature end and start times. So if neither
fc42512879dd0504532f52fe5d0d0383dda96a1eniq <code class="option">end-time</code> or <code class="option">start-time</code>
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq are specified, <span><strong class="command">dnssec-signzone</strong></span>
0451df5dc50fa5d8b3e07d92ee6a92e36a1181a5niq signatures that are valid for 30 days, with a cycle
da0442c0440caef34706e2c2f3af05cb65921cc0jailletc interval of 7.5 days. Therefore, if any existing RRSIG records
983528026996668ea295be95aedb9c7a346af470ylavic are due to expire in less than 7.5 days, they would be
06b8f183140c8e02e0974e938a05078b511d1603covener<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem The format of the input zone file.
259878293a997ff49f5ddfc53d3739cbdc25444ecovener Possible formats are <span><strong class="command">"text"</strong></span> (default)
259878293a997ff49f5ddfc53d3739cbdc25444ecovener and <span><strong class="command">"raw"</strong></span>.
259878293a997ff49f5ddfc53d3739cbdc25444ecovener This option is primarily intended to be used for dynamic
259878293a997ff49f5ddfc53d3739cbdc25444ecovener signed zones so that the dumped zone file in a non-text
15890c9306ba98f6fc243e15a3c4778ddc7d773erpluem format containing updates can be signed directly.
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin The use of this option does not make much sense for
b54b024c06a19926832d77d40ba35ad8c41e4d3dminfrin non-dynamic zones.
65967d05f839dbf27cf91d91fa79585eeae19660minfrin<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
65967d05f839dbf27cf91d91fa79585eeae19660minfrin When signing a zone with a fixed signature lifetime, all
8152945ae46857b170cb227e79bb799f4fc7710dminfrin RRSIG records issued at the time of signing expires
8152945ae46857b170cb227e79bb799f4fc7710dminfrin simultaneously. If the zone is incrementally signed, i.e.
8152945ae46857b170cb227e79bb799f4fc7710dminfrin a previously-signed zone is passed as input to the signer,
8152945ae46857b170cb227e79bb799f4fc7710dminfrin all expired signatures have to be regenerated at about the
75f5c2db254c0167a0e396254460de09b775d203trawick same time. The <code class="option">jitter</code> option specifies a
75f5c2db254c0167a0e396254460de09b775d203trawick jitter window that will be used to randomize the signature
75f5c2db254c0167a0e396254460de09b775d203trawick expire time, thus spreading incremental signature
4f0358189bfa57b8e75bd6b94db264302a8f336amrumph regeneration over time.
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick Signature lifetime jitter also to some extent benefits
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick validators and servers by spreading out cache expiration,
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick i.e. if large numbers of RRSIGs don't expire at the same time
5716f9c6daa92dde5f2f9d11ed63f7c9549c223atrawick from all caches there will be less congestion than if all
54d750a84a175d8e338880514d440773eb986b50covener validators need to refetch at mostly the same time.
54d750a84a175d8e338880514d440773eb986b50covener<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
54d750a84a175d8e338880514d440773eb986b50covener Specifies the number of threads to use. By default, one
54d750a84a175d8e338880514d440773eb986b50covener thread is started for each detected CPU.
7a3aa12f0eda24793ee26d6a179bd53132e9dae8covener<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
83b50288fa7d306324bba68832011ea08f5c7832covener The SOA serial number format of the signed zone.
4e30ef014533a7e93c92d88306291f5e49c9692ftrawick Possible formats are <span><strong class="command">"keep"</strong></span> (default),
83b50288fa7d306324bba68832011ea08f5c7832covener <span><strong class="command">"increment"</strong></span> and
5f066f496cd9f20a2a701255bc67d44e7cb46daetrawick <span><strong class="command">"unixtime"</strong></span>.
2e15620d724fb8e3a5be183b917359a2fd6e9468covener<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
2e15620d724fb8e3a5be183b917359a2fd6e9468covener<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
2e15620d724fb8e3a5be183b917359a2fd6e9468covener<dd><p>Increment the SOA serial number using RFC 1982
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
1b988c41ee505962781d110a3e4c2c90f1ea0aa4covener<dd><p>Set the SOA serial number to the number of seconds
b8efdc95bec9cf089aa1be0bfd07d46aa1137a7acovener<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd The zone origin. If not specified, the name of the zone file
f06e7c4b1bce6b6491e5de0b7998d3f5696b293dchrisd is assumed to be the origin.
179565be4043d7e5f9161aa75271fa0a001866d9covener<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
111436a32ba1254291e4883292fb116d15fe8f64covener The format of the output file containing the signed zone.
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener Possible formats are <span><strong class="command">"text"</strong></span> (default)
fce4949fb0b309a5744afcd503c6ed2d35621ee2covener and <span><strong class="command">"raw"</strong></span>.
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick Use pseudo-random data when signing the zone. This is faster,
7b7430e701e9a31ce809da7c220bb8dfcf68c86etrawick but less secure, than using real random data. This option
ccc20788c1e5fc973f36df634399c89acb70deaejerenkrantz may be useful when signing large zones or when the entropy
ccc20788c1e5fc973f36df634399c89acb70deaejerenkrantz source is limited.
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
273e512f20f262e5e2aa8e0e83371d1929fb76adjkaluza Specifies the source of randomness. If the operating
efe780dcf13b2b95effabf897d694d8f23feac74trawick system does not provide a <code class="filename">/dev/random</code>
fe83f60b41477b14a37edcfcd1f7f5c5a1ebfe44minfrin or equivalent device, the default source of randomness
fe83f60b41477b14a37edcfcd1f7f5c5a1ebfe44minfrin is keyboard input. <code class="filename">randomdev</code>
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza the name of a character device or file containing random
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza data to be used instead of the default. The special value
993d1261a278d7322bccef219101220b7b4fb8c5jkaluza <code class="filename">keyboard</code> indicates that keyboard
ba050a6f942b9fa0e81ed73437588005c569655ccovener input should be used.
135ddda3a989215d2bedbcf1529bfb269c3eda23niq Print statistics at completion.
135ddda3a989215d2bedbcf1529bfb269c3eda23niq<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
001a44c352f89c9ec332ffd3e0a6927dcd19432chumbedooh Sets the debugging level.
cc5a4a08dc9783fcbc52ce86f11e01c281a43810minfrin Ignore KSK flag on key when determining what to sign.
9b0076ddd1103e5fa9c1f9bafde4b06ce244fbaecovener<dt><span class="term">-3 <em class="replaceable"><code>salt</code></em></span></dt>
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza Generate a NSEC3 chain with the given hex encoded salt.
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza A dash (<em class="replaceable"><code>salt</code></em>) can
249d09d51808cb7981af99762c3b3736ca126cd5jkaluza be used to indicate that no salt is to be used when generating the NSEC3 chain.
56589be3d7a3e9343370df240010c6928cc78b39jkaluza<dt><span class="term">-H <em class="replaceable"><code>iterations</code></em></span></dt>
56589be3d7a3e9343370df240010c6928cc78b39jkaluza When generating a NSEC3 chain use this many interations. The
77ca16c5676da23155311e13cee61e7eaba9fa3ejailletc default is 100.
f87299dab99bc04b51a6b8cad51b6795db862c0atrawick When generating a NSEC3 chain set the OPTOUT flag on all
f87299dab99bc04b51a6b8cad51b6795db862c0atrawick NSEC3 records and do not generate NSEC3 records for insecure
f87299dab99bc04b51a6b8cad51b6795db862c0atrawick delegations.
85eacfc96a04547ef25aabbc06440039715084c2jorton The file containing the zone to be signed.
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener Specify which keys should be used to sign the zone. If
a4df2cd1e1391575a327c2a90ba4315f805a0a78covener no keys are specified, then the zone will be examined
cb666b29f81df1d11d65002250153353568021fccovener for DNSKEY records at the zone apex. If these are found and
cb666b29f81df1d11d65002250153353568021fccovener there are matching private keys, in the current directory,
cb666b29f81df1d11d65002250153353568021fccovener then these will be used for signing.
1f50dc34ae069adeed20b2986e5ffdefa5c410e0covener The following command signs the <strong class="userinput"><code>example.com</code></strong>
1f50dc34ae069adeed20b2986e5ffdefa5c410e0covener zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
1f50dc34ae069adeed20b2986e5ffdefa5c410e0covener (Kexample.com.+003+17247). The zone's keys must be in the master
63a5ea80bddcc84a462e40f402b4f330e0e05411covener file (<code class="filename">db.example.com</code>). This invocation looks
63a5ea80bddcc84a462e40f402b4f330e0e05411covener for <code class="filename">keyset</code> files, in the current directory,
63a5ea80bddcc84a462e40f402b4f330e0e05411covener so that DS records can be generated from them (<span><strong class="command">-g</strong></span>).
65a4e663b82f8bce28ac22ab2edfd7502de36998sf<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
74e7f6c55fd67b10cb400b3f6d1dc718a303d944minfrin In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
74e7f6c55fd67b10cb400b3f6d1dc718a303d944minfrin the file <code class="filename">db.example.com.signed</code>. This
74e7f6c55fd67b10cb400b3f6d1dc718a303d944minfrin file should be referenced in a zone statement in a
a511a29faf2ff7ead3b67680154a624effb31aafminfrin This example re-signs a previously signed zone with default parameters.
a511a29faf2ff7ead3b67680154a624effb31aafminfrin The private keys are assumed to be in the current directory.
63921358ef93fcb41bc71d9894221ba3d7fbb87bminfrin<pre class="programlisting">% cp db.example.com.signed db.example.com
6d601599d3d65df0410eae6e573e75b2dbfb1fb4minfrin<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
684e0cfc200f66287a93bbd1708d1dd8a92a7eefcovener <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
26c5829347f6a355c00f1ba0301d575056b69536niq<p><span class="corpauthor">Internet Systems Consortium</span>
c12917da693bae4028a1d5a5e8224bceed8c739dsf<a accesskey="p" href="man.dnssec-keygen.html">Prev</a>�</td>
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
eafcc0ebf263d0ba69855b6e10958c4c1a2361bdsf<td width="40%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
d7ffd2da16d58b1a0de212e4d56f7aebb72bef26sf<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
4576c1a9ef54cd1e5555ee07d016a7f559f80338sf<td width="40%" align="right" valign="top">�<span class="application">named-checkconf</span>