man.dnssec-signzone.html revision c3dc968140ab7f04795acc7835e4e89ccb0c0a27
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - Copyright (C) 2000-2003 Internet Software Consortium.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - Permission to use, copy, modify, and/or distribute this software for any
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - purpose with or without fee is hereby granted, provided that the above
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin - copyright notice and this permission notice appear in all copies.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin - PERFORMANCE OF THIS SOFTWARE.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<!-- $Id$ -->
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<link rel="prev" href="man.dnssec-settime.html" title="dnssec-settime">
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<link rel="next" href="man.dnssec-verify.html" title="dnssec-verify">
34f9b3eef6fdadbda0a846aa4d68691ac40eace5Roland Mainz<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
34f9b3eef6fdadbda0a846aa4d68691ac40eace5Roland Mainz<table width="100%" summary="Navigation header">
34f9b3eef6fdadbda0a846aa4d68691ac40eace5Roland Mainz<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-verify.html">Next</a>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-L <em class="replaceable"><code>serial</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-P</code>] [<code class="option">-p</code>] [<code class="option">-R</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-X <em class="replaceable"><code>extended end-time</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<p><span><strong class="command">dnssec-signzone</strong></span>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin signs a zone. It generates
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin NSEC and RRSIG records and produces a signed version of the
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin zone. The security status of delegations from the signed zone
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin (that is, whether the child zones are secure or not) is
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin determined by the presence or absence of a
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <code class="filename">keyset</code> file for each child zone.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Verify all generated signatures.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Specifies the DNS class of the zone.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Compatibility mode: Generate a
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin file in addition to
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin when signing a zone, for use by older versions of
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">dnssec-signzone</strong></span>.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <code class="filename">keyset-</code> files in <code class="option">directory</code>.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Output only those record types automatically managed by
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">dnssec-signzone</strong></span>, i.e. RRSIG, NSEC,
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin NSEC3 and NSEC3PARAM records. If smart signing
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin (<code class="option">-S</code>) is used, DNSKEY records are also
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin included. The resulting file can be included in the original
34f9b3eef6fdadbda0a846aa4d68691ac40eace5Roland Mainz zone file with <span><strong class="command">$INCLUDE</strong></span>. This option
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin cannot be combined with <code class="option">-O raw</code>,
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <code class="option">-O fast</code>, or serial number updating.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Uses a crypto hardware (OpenSSL engine) for the crypto operations
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin it supports, for instance signing with private keys from
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin a secure key store. When compiled with PKCS#11 support
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin it defaults to pkcs11; the empty name resets it to no engine.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Generate DS records for child zones from
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin file. Existing DS records will be removed.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Key repository: Specify a directory to search for DNSSEC keys.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin If not specified, defaults to the current directory.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Treat specified key as a key signing key ignoring any
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin key flags. This option may be specified multiple times.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Generate a DLV set in addition to the key (DNSKEY) and DS sets.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin The domain is appended to the name of the records.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Specify the date and time when the generated RRSIG records
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin become valid. This can be either an absolute or relative
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin time. An absolute start time is indicated by a number
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin in YYYYMMDDHHMMSS notation; 20000530144500 denotes
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin 14:45:00 UTC on May 30th, 2000. A relative start time is
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin indicated by +N, which is N seconds from the current time.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin If no <code class="option">start-time</code> is specified, the current
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin time minus 1 hour (to allow for clock skew) is used.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Specify the date and time when the generated RRSIG records
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin expire. As with <code class="option">start-time</code>, an absolute
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin time is indicated in YYYYMMDDHHMMSS notation. A time relative
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin to the start time is indicated with +N, which is N seconds from
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin the start time. A time relative to the current time is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin indicated with now+N. If no <code class="option">end-time</code> is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin specified, 30 days from the start time is used as a default.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <code class="option">end-time</code> must be later than
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-X <em class="replaceable"><code>extended end-time</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Specify the date and time when the generated RRSIG records
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin for the DNSKEY RRset will expire. This is to be used in cases
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin when the DNSKEY signatures need to persist longer than
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin signatures on other records; e.g., when the private component
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin of the KSK is kept offline and the KSK signature is to be
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin refreshed manually.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin As with <code class="option">start-time</code>, an absolute
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin time is indicated in YYYYMMDDHHMMSS notation. A time relative
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin to the start time is indicated with +N, which is N seconds from
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin the start time. A time relative to the current time is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin indicated with now+N. If no <code class="option">extended end-time</code> is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin specified, the value of <code class="option">end-time</code> is used as
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin the default. (<code class="option">end-time</code>, in turn, defaults to
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin 30 days from the start time.) <code class="option">extended end-time</code>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin must be later than <code class="option">start-time</code>.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-f <em class="replaceable"><code>output-file</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin The name of the output file containing the signed zone. The
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin default is to append <code class="filename">.signed</code> to
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin the input filename. If <code class="option">output-file</code> is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin set to <code class="literal">"-"</code>, then the signed zone is
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin written to the standard output, with a default output
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin format of "full".
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Prints a short summary of the options and arguments to
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">dnssec-signzone</strong></span>.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-i <em class="replaceable"><code>interval</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin When a previously-signed zone is passed as input, records
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin may be resigned. The <code class="option">interval</code> option
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin specifies the cycle interval as an offset from the current
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin time (in seconds). If a RRSIG record expires after the
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin cycle interval, it is retained. Otherwise, it is considered
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin to be expiring soon, and it will be replaced.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin The default cycle interval is one quarter of the difference
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin between the signature end and start times. So if neither
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <code class="option">end-time</code> or <code class="option">start-time</code>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin are specified, <span><strong class="command">dnssec-signzone</strong></span>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin signatures that are valid for 30 days, with a cycle
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin interval of 7.5 days. Therefore, if any existing RRSIG records
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin are due to expire in less than 7.5 days, they would be
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin The format of the input zone file.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Possible formats are <span><strong class="command">"text"</strong></span> (default),
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <span><strong class="command">"raw"</strong></span>, and <span><strong class="command">"fast"</strong></span>.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin This option is primarily intended to be used for dynamic
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin signed zones so that the dumped zone file in a non-text
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin format containing updates can be signed directly.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin The use of this option does not make much sense for
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin non-dynamic zones.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-j <em class="replaceable"><code>jitter</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin When signing a zone with a fixed signature lifetime, all
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin RRSIG records issued at the time of signing expires
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin simultaneously. If the zone is incrementally signed, i.e.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin a previously-signed zone is passed as input to the signer,
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin all expired signatures have to be regenerated at about the
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin same time. The <code class="option">jitter</code> option specifies a
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin jitter window that will be used to randomize the signature
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin expire time, thus spreading incremental signature
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin regeneration over time.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Signature lifetime jitter also to some extent benefits
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin validators and servers by spreading out cache expiration,
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin i.e. if large numbers of RRSIGs don't expire at the same time
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin from all caches there will be less congestion than if all
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin validators need to refetch at mostly the same time.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-L <em class="replaceable"><code>serial</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin When writing a signed zone to "raw" or "fast" format, set the
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin "source serial" value in the header to the specified serial
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin number. (This is expected to be used primarily for testing
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-n <em class="replaceable"><code>ncpus</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Specifies the number of threads to use. By default, one
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin thread is started for each detected CPU.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-N <em class="replaceable"><code>soa-serial-format</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin The SOA serial number format of the signed zone.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Possible formats are <span><strong class="command">"keep"</strong></span> (default),
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">"increment"</strong></span> and
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">"unixtime"</strong></span>.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term"><span><strong class="command">"keep"</strong></span></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term"><span><strong class="command">"increment"</strong></span></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term"><span><strong class="command">"unixtime"</strong></span></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dd><p>Set the SOA serial number to the number of seconds
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin The zone origin. If not specified, the name of the zone file
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin is assumed to be the origin.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin<dt><span class="term">-O <em class="replaceable"><code>output-format</code></em></span></dt>
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin The format of the output file containing the signed zone.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Possible formats are <span><strong class="command">"text"</strong></span> (default),
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin which is the standard textual representation of the zone;
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">"full"</strong></span>, which is text output in a
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin format suitable for processing by external scripts;
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin and <span><strong class="command">"fast"</strong></span>, <span><strong class="command">"raw"</strong></span>,
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin and <span><strong class="command">"raw=N"</strong></span>, which store the zone in
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin binary formats for rapid loading by <span><strong class="command">named</strong></span>.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin <span><strong class="command">"raw=N"</strong></span> specifies the format version of
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin the raw zone file: if N is 0, the raw file can be read by
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin any version of <span><strong class="command">named</strong></span>; if N is 1, the file
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin can be read by release 9.9.0 or higher; the default is 1.
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin Use pseudo-random data when signing the zone. This is faster,
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin but less secure, than using real random data. This option
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin may be useful when signing large zones or when the entropy
da2e3ebdc1edfbc5028edf1354e7dd2fa69a7968chin source is limited.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Disable post sign verification tests.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin The post sign verification test ensures that for each algorithm
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin in use there is at least one non revoked self signed KSK key,
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin that all revoked KSK keys are self signed, and that all records
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin in the zone are signed by the algorithm.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin This option skips these tests.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Remove signatures from keys that no longer exist.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Normally, when a previously-signed zone is passed as input
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin to the signer, and a DNSKEY record has been removed and
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin replaced with a new one, signatures from the old key
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin that are still within their validity period are retained.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin This allows the zone to continue to validate with cached
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin copies of the old DNSKEY RRset. The <code class="option">-R</code> forces
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <span><strong class="command">dnssec-signzone</strong></span> to remove all orphaned
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin<dt><span class="term">-r <em class="replaceable"><code>randomdev</code></em></span></dt>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Specifies the source of randomness. If the operating
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin system does not provide a <code class="filename">/dev/random</code>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin or equivalent device, the default source of randomness
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin is keyboard input. <code class="filename">randomdev</code>
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin the name of a character device or file containing random
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin data to be used instead of the default. The special value
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin <code class="filename">keyboard</code> indicates that keyboard
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin input should be used.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin Smart signing: Instructs <span><strong class="command">dnssec-signzone</strong></span> to
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin search the key repository for keys that match the zone being
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin signed, and to include them in the zone if appropriate.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin When a key is found, its timing metadata is examined to
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin determine how it should be used, according to the following
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin rules. Each successive rule takes priority over the prior
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin If no timing metadata has been set for the key, the key is
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin published in the zone and used to sign the zone.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin If the key's publication date is set and is in the past, the
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin key is published in the zone.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin If the key's activation date is set and in the past, the
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin key is published (regardless of publication date) and
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin used to sign the zone.
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin If the key's revocation date is set and in the past, and the
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin key is published, then the key is revoked, and the revoked key
7c2fbfb345896881c631598ee3852ce9ce33fb07April Chin is used to sign the zone.
Kexample.com.+003+17247