man.dnssec-signzone.html revision aa6c5a3e331958d3c92c2facdbd2b8daa55b5959
c25356d5978632df6203437e1953bcb29e0c736fTimo Sirainen - Copyright (C) 2004-2015 Internet Systems Consortium, Inc. ("ISC")
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen - Copyright (C) 2000-2003 Internet Software Consortium.
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen - Permission to use, copy, modify, and/or distribute this software for any
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - purpose with or without fee is hereby granted, provided that the above
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - copyright notice and this permission notice appear in all copies.
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
3809b9691c46926aa54968ac8e418d04361e1efaTimo Sirainen - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
3809b9691c46926aa54968ac8e418d04361e1efaTimo Sirainen - PERFORMANCE OF THIS SOFTWARE.
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
579e70631b8474d20fd3829f477c62950e5f9635Timo Sirainen<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen<link rel="prev" href="man.dnssec-settime.html" title="dnssec-settime">
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<link rel="next" href="man.dnssec-verify.html" title="dnssec-verify">
da9f6acdcb303d0fe5160b669668aedf39c8f45aTimo Sirainen<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<table width="100%" summary="Navigation header">
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
eb4d4f557fa75aa2a47639e9deb75a21f44eb42aTimo Sirainen<th width="60%" align="center">Manual pages</th>
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-verify.html">Next</a>
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
e7ca5f820d6a1a8fe549a2966ac707a60e055ef4Timo Sirainen<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-L <em class="replaceable"><code>serial</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-M <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-P</code>] [<code class="option">-p</code>] [<code class="option">-Q</code>] [<code class="option">-R</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-X <em class="replaceable"><code>extended end-time</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
8ab69d02c689fbdad2a1c83a5cd27e6adf21ca6cTimo Sirainen<p><span><strong class="command">dnssec-signzone</strong></span>
8ab69d02c689fbdad2a1c83a5cd27e6adf21ca6cTimo Sirainen signs a zone. It generates
7705148680904051b573a9125ecee765032a5809Timo Sirainen NSEC and RRSIG records and produces a signed version of the
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen zone. The security status of delegations from the signed zone
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen (that is, whether the child zones are secure or not) is
3809b9691c46926aa54968ac8e418d04361e1efaTimo Sirainen determined by the presence or absence of a
0dffa25d211be541ee3c953b23566a1a990789dfTimo Sirainen <code class="filename">keyset</code> file for each child zone.
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen Verify all generated signatures.
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen Specifies the DNS class of the zone.
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen Compatibility mode: Generate a
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
e293d46ffe09252ae50704b2a53be6e5b9bdc778Timo Sirainen file in addition to
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
e293d46ffe09252ae50704b2a53be6e5b9bdc778Timo Sirainen when signing a zone, for use by older versions of
e293d46ffe09252ae50704b2a53be6e5b9bdc778Timo Sirainen <span><strong class="command">dnssec-signzone</strong></span>.
7fb70daba4e571eab5b64f496d20b9e37e31141bTimo Sirainen<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
7d8afd1e15bdf23b5fd13aa9ac9606aca2797125Timo Sirainen Look for <code class="filename">dsset-</code> or
7d8afd1e15bdf23b5fd13aa9ac9606aca2797125Timo Sirainen <code class="filename">keyset-</code> files in <code class="option">directory</code>.
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen Output only those record types automatically managed by
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen <span><strong class="command">dnssec-signzone</strong></span>, i.e. RRSIG, NSEC,
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen NSEC3 and NSEC3PARAM records. If smart signing
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen (<code class="option">-S</code>) is used, DNSKEY records are also
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen included. The resulting file can be included in the original
02a54da28f376dd66d7939d8546a196a0045b486Timo Sirainen zone file with <span><strong class="command">$INCLUDE</strong></span>. This option
515d649c1802beb48433b90125518c00d0a1fbb4Timo Sirainen cannot be combined with <code class="option">-O raw</code>,
2f122b4db3f0d4eeb59ff9d306e54b2009d72cf9Timo Sirainen <code class="option">-O map</code>, or serial number updating.
81e6e1ef0feef60644a4c4b745d82a4c98223affTimo Sirainen<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
7d8afd1e15bdf23b5fd13aa9ac9606aca2797125Timo Sirainen When applicable, specifies the hardware to use for
eb4d4f557fa75aa2a47639e9deb75a21f44eb42aTimo Sirainen cryptographic operations, such as a secure key store used
15f43b172d2c626aa03c921979c49821a55c7e5eTimo Sirainen When BIND is built with OpenSSL PKCS#11 support, this defaults
15f43b172d2c626aa03c921979c49821a55c7e5eTimo Sirainen to the string "pkcs11", which identifies an OpenSSL engine
4c158400b046fefefce0194603951a6587f51867Timo Sirainen that can drive a cryptographic accelerator or hardware service
4c158400b046fefefce0194603951a6587f51867Timo Sirainen module. When BIND is built with native PKCS#11 cryptography
cc287b822b175619a853686b738ba673e370117bTimo Sirainen (--enable-native-pkcs11), it defaults to the path of the PKCS#11
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen provider library specified via "--with-pkcs11".
cc287b822b175619a853686b738ba673e370117bTimo Sirainen Generate DS records for child zones from
cc287b822b175619a853686b738ba673e370117bTimo Sirainen <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
cc287b822b175619a853686b738ba673e370117bTimo Sirainen file. Existing DS records will be removed.
cc287b822b175619a853686b738ba673e370117bTimo Sirainen<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen Key repository: Specify a directory to search for DNSSEC keys.
086c52e4bcdc950e47ee331e1e07c9c10982a670Timo Sirainen If not specified, defaults to the current directory.
7d8afd1e15bdf23b5fd13aa9ac9606aca2797125Timo Sirainen<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
signatures on other records; e.g., when the private component
<span><strong class="command">"raw"</strong></span>, and <span><strong class="command">"map"</strong></span>.
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
<span><strong class="command">"increment"</strong></span>, <span><strong class="command">"unixtime"</strong></span>,
and <span><strong class="command">"map"</strong></span>, <span><strong class="command">"raw"</strong></span>,
Kexample.com.+003+17247