man.dnssec-signzone.html revision 82d13321f4dcc79a9aec992c7a1c4aaff8983ada
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - Copyright (C) 2004-2010 Internet Systems Consortium, Inc. ("ISC")
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - Copyright (C) 2000-2003 Internet Software Consortium.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - Permission to use, copy, modify, and/or distribute this software for any
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - purpose with or without fee is hereby granted, provided that the above
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - copyright notice and this permission notice appear in all copies.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff - PERFORMANCE OF THIS SOFTWARE.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<!-- $Id: man.dnssec-signzone.html,v 1.165 2010/08/12 01:14:28 tbox Exp $ -->
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
eb9158dea141f092a53bcc111a8e965b42fa9502jvergara<link rel="prev" href="man.dnssec-settime.html" title="dnssec-settime">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<link rel="next" href="man.named-checkconf.html" title="named-checkconf">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<td width="20%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-p</code>] [<code class="option">-P</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<p><span><strong class="command">dnssec-signzone</strong></span>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff signs a zone. It generates
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff NSEC and RRSIG records and produces a signed version of the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff zone. The security status of delegations from the signed zone
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff (that is, whether the child zones are secure or not) is
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff determined by the presence or absence of a
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">keyset</code> file for each child zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Verify all generated signatures.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specifies the DNS class of the zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Compatibility mode: Generate a
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff file in addition to
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff when signing a zone, for use by older versions of
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">dnssec-signzone</strong></span>.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">keyset-</code> files in <code class="option">directory</code>.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Uses a crypto hardware (OpenSSL engine) for the crypto operations
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff it supports, for instance signing with private keys from
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff a secure key store. When compiled with PKCS#11 support
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff it defaults to pkcs11; the empty name resets it to no engine.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Generate DS records for child zones from
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff file. Existing DS records will be removed.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Key repository: Specify a directory to search for DNSSEC keys.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If not specified, defaults to the current directory.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Treat specified key as a key signing key ignoring any
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff key flags. This option may be specified multiple times.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Generate a DLV set in addition to the key (DNSKEY) and DS sets.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The domain is appended to the name of the records.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specify the date and time when the generated RRSIG records
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff become valid. This can be either an absolute or relative
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff time. An absolute start time is indicated by a number
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff in YYYYMMDDHHMMSS notation; 20000530144500 denotes
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff 14:45:00 UTC on May 30th, 2000. A relative start time is
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff indicated by +N, which is N seconds from the current time.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If no <code class="option">start-time</code> is specified, the current
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff time minus 1 hour (to allow for clock skew) is used.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specify the date and time when the generated RRSIG records
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff expire. As with <code class="option">start-time</code>, an absolute
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff time is indicated in YYYYMMDDHHMMSS notation. A time relative
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff to the start time is indicated with +N, which is N seconds from
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff the start time. A time relative to the current time is
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff indicated with now+N. If no <code class="option">end-time</code> is
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff specified, 30 days from the start time is used as a default.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="option">end-time</code> must be later than
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The name of the output file containing the signed zone. The
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff default is to append <code class="filename">.signed</code> to
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff input filename.
b610c3e7694ee7d23d00c046d9cdc37989102492jvergara Prints a short summary of the options and arguments to
b610c3e7694ee7d23d00c046d9cdc37989102492jvergara <span><strong class="command">dnssec-signzone</strong></span>.
b610c3e7694ee7d23d00c046d9cdc37989102492jvergara<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
b610c3e7694ee7d23d00c046d9cdc37989102492jvergara When a previously-signed zone is passed as input, records
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff may be resigned. The <code class="option">interval</code> option
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff specifies the cycle interval as an offset from the current
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff time (in seconds). If a RRSIG record expires after the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff cycle interval, it is retained. Otherwise, it is considered
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff to be expiring soon, and it will be replaced.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The default cycle interval is one quarter of the difference
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff between the signature end and start times. So if neither
b610c3e7694ee7d23d00c046d9cdc37989102492jvergara <code class="option">end-time</code> or <code class="option">start-time</code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff are specified, <span><strong class="command">dnssec-signzone</strong></span>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff signatures that are valid for 30 days, with a cycle
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff interval of 7.5 days. Therefore, if any existing RRSIG records
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff are due to expire in less than 7.5 days, they would be
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The format of the input zone file.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Possible formats are <span><strong class="command">"text"</strong></span> (default)
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff and <span><strong class="command">"raw"</strong></span>.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff This option is primarily intended to be used for dynamic
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff signed zones so that the dumped zone file in a non-text
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff format containing updates can be signed directly.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The use of this option does not make much sense for
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff non-dynamic zones.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff When signing a zone with a fixed signature lifetime, all
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff RRSIG records issued at the time of signing expires
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff simultaneously. If the zone is incrementally signed, i.e.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff a previously-signed zone is passed as input to the signer,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff all expired signatures have to be regenerated at about the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff same time. The <code class="option">jitter</code> option specifies a
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff jitter window that will be used to randomize the signature
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff expire time, thus spreading incremental signature
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff regeneration over time.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Signature lifetime jitter also to some extent benefits
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff validators and servers by spreading out cache expiration,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff i.e. if large numbers of RRSIGs don't expire at the same time
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff from all caches there will be less congestion than if all
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff validators need to refetch at mostly the same time.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specifies the number of threads to use. By default, one
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff thread is started for each detected CPU.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The SOA serial number format of the signed zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Possible formats are <span><strong class="command">"keep"</strong></span> (default),
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">"increment"</strong></span> and
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">"unixtime"</strong></span>.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dd><p>Set the SOA serial number to the number of seconds
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The zone origin. If not specified, the name of the zone file
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff is assumed to be the origin.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The format of the output file containing the signed zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Possible formats are <span><strong class="command">"text"</strong></span> (default)
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff and <span><strong class="command">"raw"</strong></span>.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Use pseudo-random data when signing the zone. This is faster,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff but less secure, than using real random data. This option
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff may be useful when signing large zones or when the entropy
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff source is limited.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Disable post sign verification tests.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The post sign verification test ensures that for each algorithm
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff in use there is at least one non revoked self signed KSK key,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff that all revoked KSK keys are self signed, and that all records
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff in the zone are signed by the algorithm.
461ce636eb2a5877e5811bcced654e66606de0fcjvergara This option skips these tests.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specifies the source of randomness. If the operating
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff system does not provide a <code class="filename">/dev/random</code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff or equivalent device, the default source of randomness
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff is keyboard input. <code class="filename">randomdev</code>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff the name of a character device or file containing random
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff data to be used instead of the default. The special value
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="filename">keyboard</code> indicates that keyboard
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff input should be used.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Smart signing: Instructs <span><strong class="command">dnssec-signzone</strong></span> to
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff search the key repository for keys that match the zone being
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff signed, and to include them in the zone if appropriate.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff When a key is found, its timing metadata is examined to
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff determine how it should be used, according to the following
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff rules. Each successive rule takes priority over the prior
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If no timing metadata has been set for the key, the key is
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff published in the zone and used to sign the zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If the key's publication date is set and is in the past, the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff key is published in the zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If the key's activation date is set and in the past, the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff key is published (regardless of publication date) and
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff used to sign the zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If the key's revocation date is set and in the past, and the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff key is published, then the key is revoked, and the revoked key
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff is used to sign the zone.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff If either of the key's unpublication or deletion dates are set
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff and in the past, the key is NOT published or used to sign the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff zone, regardless of any other metadata.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-T <em class="replaceable"><code>ttl</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specifies the TTL to be used for new DNSKEY records imported
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff into the zone from the key repository. If not specified,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff the default is the minimum TTL value from the zone's SOA
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff record. This option is ignored when signing without
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <code class="option">-S</code>, since DNSKEY records are not imported
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff from the key repository in that case. It is also ignored if
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff there are any pre-existing DNSKEY records at the zone apex,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff in which case new records' TTL values will be set to match
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Print statistics at completion.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Update NSEC/NSEC3 chain when re-signing a previously signed
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff zone. With this option, a zone signed with NSEC can be
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff switched to NSEC3, or a zone signed with NSEC3 can
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff be switch to NSEC or to NSEC3 with different parameters.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Without this option, <span><strong class="command">dnssec-signzone</strong></span> will
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff retain the existing chain when re-signing.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Sets the debugging level.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Only sign the DNSKEY RRset with key-signing keys, and omit
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff signatures from zone-signing keys. (This is similar to the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">dnssec-dnskey-kskonly yes;</strong></span> zone option in
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">named</strong></span>.)
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Ignore KSK flag on key when determining what to sign. This
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff causes KSK-flagged keys to sign all records, not just the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff DNSKEY RRset. (This is similar to the
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">update-check-ksk no;</strong></span> zone option in
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <span><strong class="command">named</strong></span>.)
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-3 <em class="replaceable"><code>salt</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Generate an NSEC3 chain with the given hex encoded salt.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff A dash (<em class="replaceable"><code>salt</code></em>) can
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff be used to indicate that no salt is to be used when generating the NSEC3 chain.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<dt><span class="term">-H <em class="replaceable"><code>iterations</code></em></span></dt>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff When generating an NSEC3 chain, use this many interations. The
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff default is 10.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff When generating an NSEC3 chain set the OPTOUT flag on all
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff NSEC3 records and do not generate NSEC3 records for insecure
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff delegations.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Using this option twice (i.e., <code class="option">-AA</code>)
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff turns the OPTOUT flag off for all records. This is useful
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff when using the <code class="option">-u</code> option to modify an NSEC3
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff chain which previously had OPTOUT set.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The file containing the zone to be signed.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff Specify which keys should be used to sign the zone. If
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff no keys are specified, then the zone will be examined
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff for DNSKEY records at the zone apex. If these are found and
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff there are matching private keys, in the current directory,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff then these will be used for signing.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The following command signs the <strong class="userinput"><code>example.com</code></strong>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff zone with the DSA key generated by <span><strong class="command">dnssec-keygen</strong></span>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff (Kexample.com.+003+17247). Because the <span><strong class="command">-S</strong></span> option
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff is not being used, the zone's keys must be in the master file
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff (<code class="filename">db.example.com</code>). This invocation looks
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff for <code class="filename">dsset</code> files, in the current directory,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff so that DS records can be imported from them (<span><strong class="command">-g</strong></span>).
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<pre class="programlisting">% dnssec-signzone -g -o example.com db.example.com \
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff In the above example, <span><strong class="command">dnssec-signzone</strong></span> creates
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff the file <code class="filename">db.example.com.signed</code>. This
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff file should be referenced in a zone statement in a
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff This example re-signs a previously signed zone with default parameters.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff The private keys are assumed to be in the current directory.
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<pre class="programlisting">% cp db.example.com.signed db.example.com
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<p><span class="corpauthor">Internet Systems Consortium</span>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<td width="40%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
d25372dc8e65a9ed019a88fdf659ca61313f1b31jcduff<td width="40%" align="right" valign="top">�<span class="application">named-checkconf</span>