man.dnssec-signzone.html revision c3dc968140ab7f04795acc7835e4e89ccb0c0a27
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - Copyright (C) 2004-2012 Internet Systems Consortium, Inc. ("ISC")
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - Copyright (C) 2000-2003 Internet Software Consortium.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - Permission to use, copy, modify, and/or distribute this software for any
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - purpose with or without fee is hereby granted, provided that the above
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - copyright notice and this permission notice appear in all copies.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee - PERFORMANCE OF THIS SOFTWARE.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<!-- $Id$ -->
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<link rel="prev" href="man.dnssec-settime.html" title="dnssec-settime">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<link rel="next" href="man.dnssec-verify.html" title="dnssec-verify">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<tr><th colspan="3" align="center"><span class="application">dnssec-signzone</span></th></tr>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<a accesskey="p" href="man.dnssec-settime.html">Prev</a>�</td>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<td width="20%" align="right">�<a accesskey="n" href="man.dnssec-verify.html">Next</a>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<a name="man.dnssec-signzone"></a><div class="titlepage"></div>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<p><span class="application">dnssec-signzone</span> — DNSSEC zone signing tool</p>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<div class="cmdsynopsis"><p><code class="command">dnssec-signzone</code> [<code class="option">-a</code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-D</code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-e <em class="replaceable"><code>end-time</code></em></code>] [<code class="option">-f <em class="replaceable"><code>output-file</code></em></code>] [<code class="option">-g</code>] [<code class="option">-h</code>] [<code class="option">-K <em class="replaceable"><code>directory</code></em></code>] [<code class="option">-k <em class="replaceable"><code>key</code></em></code>] [<code class="option">-L <em class="replaceable"><code>serial</code></em></code>] [<code class="option">-l <em class="replaceable"><code>domain</code></em></code>] [<code class="option">-i <em class="replaceable"><code>interval</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-j <em class="replaceable"><code>jitter</code></em></code>] [<code class="option">-N <em class="replaceable"><code>soa-serial-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-O <em class="replaceable"><code>output-format</code></em></code>] [<code class="option">-P</code>] [<code class="option">-p</code>] [<code class="option">-R</code>] [<code class="option">-r <em class="replaceable"><code>randomdev</code></em></code>] [<code class="option">-S</code>] [<code class="option">-s <em class="replaceable"><code>start-time</code></em></code>] [<code class="option">-T <em class="replaceable"><code>ttl</code></em></code>] [<code class="option">-t</code>] [<code class="option">-u</code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-X <em class="replaceable"><code>extended end-time</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] [<code class="option">-3 <em class="replaceable"><code>salt</code></em></code>] [<code class="option">-H <em class="replaceable"><code>iterations</code></em></code>] [<code class="option">-A</code>] {zonefile} [key...]</p></div>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<p><span><strong class="command">dnssec-signzone</strong></span>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee signs a zone. It generates
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee NSEC and RRSIG records and produces a signed version of the
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee zone. The security status of delegations from the signed zone
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee (that is, whether the child zones are secure or not) is
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee determined by the presence or absence of a
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="filename">keyset</code> file for each child zone.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Verify all generated signatures.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Specifies the DNS class of the zone.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Compatibility mode: Generate a
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="filename">keyset-<em class="replaceable"><code>zonename</code></em></code>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee file in addition to
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="filename">dsset-<em class="replaceable"><code>zonename</code></em></code>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee when signing a zone, for use by older versions of
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <span><strong class="command">dnssec-signzone</strong></span>.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="filename">keyset-</code> files in <code class="option">directory</code>.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Output only those record types automatically managed by
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <span><strong class="command">dnssec-signzone</strong></span>, i.e. RRSIG, NSEC,
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee NSEC3 and NSEC3PARAM records. If smart signing
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee (<code class="option">-S</code>) is used, DNSKEY records are also
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee included. The resulting file can be included in the original
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee zone file with <span><strong class="command">$INCLUDE</strong></span>. This option
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee cannot be combined with <code class="option">-O raw</code>,
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="option">-O fast</code>, or serial number updating.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Uses a crypto hardware (OpenSSL engine) for the crypto operations
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee it supports, for instance signing with private keys from
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee a secure key store. When compiled with PKCS#11 support
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee it defaults to pkcs11; the empty name resets it to no engine.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Generate DS records for child zones from
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="filename">dsset-</code> or <code class="filename">keyset-</code>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee file. Existing DS records will be removed.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-K <em class="replaceable"><code>directory</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Key repository: Specify a directory to search for DNSSEC keys.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee If not specified, defaults to the current directory.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-k <em class="replaceable"><code>key</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Treat specified key as a key signing key ignoring any
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee key flags. This option may be specified multiple times.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-l <em class="replaceable"><code>domain</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Generate a DLV set in addition to the key (DNSKEY) and DS sets.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee The domain is appended to the name of the records.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-s <em class="replaceable"><code>start-time</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Specify the date and time when the generated RRSIG records
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee become valid. This can be either an absolute or relative
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee time. An absolute start time is indicated by a number
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee in YYYYMMDDHHMMSS notation; 20000530144500 denotes
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee 14:45:00 UTC on May 30th, 2000. A relative start time is
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee indicated by +N, which is N seconds from the current time.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee If no <code class="option">start-time</code> is specified, the current
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee time minus 1 hour (to allow for clock skew) is used.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-e <em class="replaceable"><code>end-time</code></em></span></dt>
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee Specify the date and time when the generated RRSIG records
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee expire. As with <code class="option">start-time</code>, an absolute
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee time is indicated in YYYYMMDDHHMMSS notation. A time relative
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee to the start time is indicated with +N, which is N seconds from
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee the start time. A time relative to the current time is
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee indicated with now+N. If no <code class="option">end-time</code> is
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee specified, 30 days from the start time is used as a default.
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee <code class="option">end-time</code> must be later than
23b5c241225a8ade2b6b9f06ebb891ee459e3b02tomee<dt><span class="term">-X <em class="replaceable"><code>extended end-time</code></em></span></dt>
signatures on other records; e.g., when the private component
<span><strong class="command">"raw"</strong></span>, and <span><strong class="command">"fast"</strong></span>.
simultaneously. If the zone is incrementally signed, i.e.
i.e. if large numbers of RRSIGs don't expire at the same time
and <span><strong class="command">"fast"</strong></span>, <span><strong class="command">"raw"</strong></span>,
Kexample.com.+003+17247