man.dnssec-verify.html revision 1ca759b3f5c0672b2a66bc02288fe010cabbfe37
436aad11e01e916f75e68a2e9cb89ac217a990d3Tinderbox User<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">
6fe48fb46e53ffc37542853a1edb74cb481b7d94Automatic Updater<!--
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User - Copyright (C) 2000-2015 Internet Systems Consortium, Inc. ("ISC")
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User -
e9e4257668ff6c4e583b0c0db2508650b0b677b8Tinderbox User - This Source Code Form is subject to the terms of the Mozilla Public
e9e4257668ff6c4e583b0c0db2508650b0b677b8Tinderbox User - License, v. 2.0. If a copy of the MPL was not distributed with this
c57668a2fbbe558c1bd21652813616f2f517c469Tinderbox User - file, You can obtain one at http://mozilla.org/MPL/2.0/.
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews-->
1f4c645185bd8fc70048e0a69eee46193a284e5cTinderbox User<html lang="en">
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<head>
bed0874e1a09e810575328c4bfc346a47514b69fMark Andrews<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User<title>dnssec-verify</title>
b886b04d8d2b085cbf3e1bf4442dee87f43ba5e4Tinderbox User<meta name="generator" content="DocBook XSL Stylesheets V1.78.1">
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<link rel="home" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<link rel="up" href="Bv9ARM.ch13.html" title="Manual pages">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<link rel="prev" href="man.dnssec-signzone.html" title="dnssec-signzone">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<link rel="next" href="man.lwresd.html" title="lwresd">
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews</head>
a7c412f37cc73d0332887a746e81220cbf09dd00Mark Andrews<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<div class="navheader">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<table width="100%" summary="Navigation header">
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<tr><th colspan="3" align="center"><span class="application">dnssec-verify</span></th></tr>
e676a596869d8a80a644c99a848afb53d1c5975eMark Andrews<tr>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<td width="20%" align="left">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<th width="60%" align="center">Manual pages</th>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<td width="20%" align="right">�<a accesskey="n" href="man.lwresd.html">Next</a>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews</td>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User</tr>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews</table>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<hr>
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews</div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<div class="refentry">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<a name="man.dnssec-verify"></a><div class="titlepage"></div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<div class="refnamediv">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<h2>Name</h2>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<p><span class="application">dnssec-verify</span> &#8212; DNSSEC zone verification tool</p>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User</div>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<div class="refsynopsisdiv">
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<h2>Synopsis</h2>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<div class="cmdsynopsis"><p><code class="command">dnssec-verify</code> [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-x</code>] [<code class="option">-z</code>] {zonefile}</p></div>
b886b04d8d2b085cbf3e1bf4442dee87f43ba5e4Tinderbox User</div>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<div class="refsection">
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<a name="id-1.14.17.7"></a><h2>DESCRIPTION</h2>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<p><span class="command"><strong>dnssec-verify</strong></span>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User verifies that a zone is fully signed for each algorithm found
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt in the DNSKEY RRset for the zone, and that the NSEC / NSEC3
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater chains are complete.
16f6050f29b6b0422cee858e609f65e474e70ef2Tinderbox User </p>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater</div>
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<div class="refsection">
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<a name="id-1.14.17.8"></a><h2>OPTIONS</h2>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<div class="variablelist"><dl class="variablelist">
aa9c561961e9d877946ebaa8795fa2be054ab7bfEvan Hunt<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
710bce1a85c96e85ca1a90471382055acd29d51fTinderbox User<dd><p>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater Specifies the DNS class of the zone.
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </p></dd>
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<dd>
cdfc81e048bd34c1d628380247bda6b80a89e20eAutomatic Updater<p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews Specifies the cryptographic hardware to use, when applicable.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews </p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews When BIND is built with OpenSSL PKCS#11 support, this defaults
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater to the string "pkcs11", which identifies an OpenSSL engine
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews that can drive a cryptographic accelerator or hardware service
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews module. When BIND is built with native PKCS#11 cryptography
16f6050f29b6b0422cee858e609f65e474e70ef2Tinderbox User (--enable-native-pkcs11), it defaults to the path of the PKCS#11
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews provider library specified via "--with-pkcs11".
9513a2a6670951f5cf5477fcfec9f933fcaff628Automatic Updater </p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews</dd>
eabc9c3c07cd956d3c436bd7614cb162dabdda76Mark Andrews<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<dd><p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews The format of the input zone file.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews Possible formats are <span class="command"><strong>"text"</strong></span> (default)
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews and <span class="command"><strong>"raw"</strong></span>.
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User This option is primarily intended to be used for dynamic
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User signed zones so that the dumped zone file in a non-text
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User format containing updates can be verified independently.
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User The use of this option does not make much sense for
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User non-dynamic zones.
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User </p></dd>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<dd><p>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User The zone origin. If not specified, the name of the zone file
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User is assumed to be the origin.
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User </p></dd>
b886b04d8d2b085cbf3e1bf4442dee87f43ba5e4Tinderbox User<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<dd><p>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Sets the debugging level.
950d203b64f512b85fcc093ee1e9e3e531a1aea3Tinderbox User </p></dd>
27739dd25026283c24645c8a1044b95ef9eb5ac6Tinderbox User<dt><span class="term">-V</span></dt>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<dd><p>
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User Prints version information.
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews </p></dd>
7a6494cfb6cc7d3f67af07359561e05e6bb8c0edTinderbox User<dt><span class="term">-x</span></dt>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<dd><p>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews Only verify that the DNSKEY RRset is signed with key-signing
18920d790825d96ca3943aa2dcb6eb80dc611c5fTinderbox User keys. Without this flag, it is assumed that the DNSKEY RRset
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews will be signed by all active keys. When this flag is set,
7a6494cfb6cc7d3f67af07359561e05e6bb8c0edTinderbox User it will not be an error if the DNSKEY RRset is not signed
77932ac533c711eca5cd86de4e7eca8d91102b43Tinderbox User by zone-signing keys. This corresponds to the <code class="option">-x</code>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews option in <span class="command"><strong>dnssec-signzone</strong></span>.
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User </p></dd>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson<dt><span class="term">-z</span></dt>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<dd>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<p>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User Ignore the KSK flag on the keys when determining whether
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews the zone if correctly signed. Without this flag it is
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User assumed that there will be a non-revoked, self-signed
efb0e886f18894a1d2489f1ad74ad14b579e11c7Mark Andrews DNSKEY with the KSK flag set for each algorithm and
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews that RRsets other than DNSKEY RRset will be signed with
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User a different DNSKEY without the KSK flag set.
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews </p>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<p>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson With this flag set, we only require that for each algorithm,
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User there will be at least one non-revoked, self-signed DNSKEY,
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews regardless of the KSK flag state, and that other RRsets
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User will be signed by a non-revoked key for the same algorithm
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews that includes the self-signed key; the same key may be used
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User for both purposes. This corresponds to the <code class="option">-z</code>
91216cff91b34c9ff6e846dc23f248219cafe660Andreas Gustafsson option in <span class="command"><strong>dnssec-signzone</strong></span>.
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User </p>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews</dd>
9ecb5d33470ebfb3719a1b8d56bcefdf4b27f7b2Tinderbox User<dt><span class="term">zonefile</span></dt>
0eb371ca0dab50ae3462e98794a6126198c52f4bMark Andrews<dd><p>
28a5dd720187fddb16055a0f64b63a7b66f29f64Mark Andrews The file containing the zone to be signed.
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews </p></dd>
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews</dl></div>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews</div>
0e573cdd111e060e5f6c18249b5ccacbe8abe278Tinderbox User<div class="refsection">
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews<a name="id-1.14.17.9"></a><h2>SEE ALSO</h2>
28a5dd720187fddb16055a0f64b63a7b66f29f64Mark Andrews<p>
37d8e0a4455876fe1e4cca511076cc2c5ab9eedeTinderbox User <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
37d8e0a4455876fe1e4cca511076cc2c5ab9eedeTinderbox User <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
28a5dd720187fddb16055a0f64b63a7b66f29f64Mark Andrews <em class="citetitle">RFC 4033</em>.
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont </p>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews</div>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews</div>
2a31bd531072824ef252c18303859d6af7451b00Francis Dupont<div class="navfooter">
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<hr>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<table width="100%" summary="Navigation footer">
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<tr>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<td width="40%" align="left">
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch13.html">Up</a></td>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<td width="40%" align="right">�<a accesskey="n" href="man.lwresd.html">Next</a>
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews</td>
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews</tr>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<tr>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<td width="40%" align="left" valign="top">
78f3ed4bc2fcd3d270bfd599804f3b27a1db4d91Mark Andrews<span class="application">dnssec-signzone</span>�</td>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User<td width="40%" align="right" valign="top">�<span class="application">lwresd</span>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews</td>
c651f15b30f1dae5cc2f00878fb5da5b3a35a468Mark Andrews</tr>
e20788e1216ed720aefa84f3295f7899d9f28c22Mark Andrews</table>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews</div>
dedefc0bdbb4e6e39eeb98aa2fc6883efec2ddb0Mark Andrews<p xmlns:db="http://docbook.org/ns/docbook" style="text-align: center;">BIND 9.11.0</p>
01a5c5503482fb3ba52088bf0178a7213273bf96Mark Andrews</body>
dc238a06bffa79de141ee7655765e2df91498a8aTinderbox User</html>
37d8e0a4455876fe1e4cca511076cc2c5ab9eedeTinderbox User