man.dnssec-verify.html revision 2fa992d017c027173a47c834db88bef10df453c0
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<!--
5690d2f46bf6dedb53d41f888e290df0526f32b1kess - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
5690d2f46bf6dedb53d41f888e290df0526f32b1kess - Copyright (C) 2000-2003 Internet Software Consortium.
5690d2f46bf6dedb53d41f888e290df0526f32b1kess -
5690d2f46bf6dedb53d41f888e290df0526f32b1kess - Permission to use, copy, modify, and/or distribute this software for any
5690d2f46bf6dedb53d41f888e290df0526f32b1kess - purpose with or without fee is hereby granted, provided that the above
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd - copyright notice and this permission notice appear in all copies.
96ad5d81ee4a2cc66a4ae19893efc8aa6d06fae7jailletc -
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
2e545ce2450a9953665f701bb05350f0d3f26275nd - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
d29d9ab4614ff992b0e8de6e2b88d52b6f1f153erbowen - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd - PERFORMANCE OF THIS SOFTWARE.
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd-->
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<!-- $Id$ -->
af33a4994ae2ff15bc67d19ff1a7feb906745bf8rbowen<html>
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<head>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<title>dnssec-verify</title>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
3f08db06526d6901aa08c110b5bc7dde6bc39905nd<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
3b3b7fc78d1f5bfc2769903375050048ff41ff26nd<link rel="prev" href="man.dnssec-signzone.html" title="dnssec-signzone">
ad74a0524a06bfe11b7de9e3b4ce7233ab3bd3f7nd<link rel="next" href="man.named-checkconf.html" title="named-checkconf">
ad74a0524a06bfe11b7de9e3b4ce7233ab3bd3f7nd</head>
9472e4d3c410be3b3f1addbf3b1db1769f64e765nd<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
c04f76acce77126cf88b09350e56ea8c6b4a064enilgun<div class="navheader">
ad74a0524a06bfe11b7de9e3b4ce7233ab3bd3f7nd<table width="100%" summary="Navigation header">
63f06dce77bb2d9b1c5aa5deeb47a1069987fd1end<tr><th colspan="3" align="center"><span class="application">dnssec-verify</span></th></tr>
d474d8ef01ec5c2a09341cd148851ed383c3287crbowen<tr>
d474d8ef01ec5c2a09341cd148851ed383c3287crbowen<td width="20%" align="left">
3b3b7fc78d1f5bfc2769903375050048ff41ff26nd<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<th width="60%" align="center">Manual pages</th>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<td width="20%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
070236a4f78e1e945e24b7265a37474dfa6a9d71kess</td>
3f08db06526d6901aa08c110b5bc7dde6bc39905nd</tr>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd</table>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<hr>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd</div>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<div class="refentry" lang="en">
9294268d4d5ac750389453cca2639520a05df6d2kess<a name="man.dnssec-verify"></a><div class="titlepage"></div>
aaf75c27909404147cc0edb74491770e3741c195nd<div class="refnamediv">
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<h2>Name</h2>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<p><span class="application">dnssec-verify</span> &#8212; DNSSEC zone verification tool</p>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd</div>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<div class="refsynopsisdiv">
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<h2>Synopsis</h2>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<div class="cmdsynopsis"><p><code class="command">dnssec-verify</code> [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-V</code>] [<code class="option">-x</code>] [<code class="option">-z</code>] {zonefile}</p></div>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd</div>
42b4935758df9d0b97689036ae76bdaa02dea031nd<div class="refsect1" lang="en">
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<a name="id2641134"></a><h2>DESCRIPTION</h2>
726b11c595edf0b0b71d0d39a2bc9d912c0ee4b5nd<p><span><strong class="command">dnssec-verify</strong></span>
8f057347a12e831fdf567da83de2fa581580298dnd verifies that a zone is fully signed for each algorithm found
8f057347a12e831fdf567da83de2fa581580298dnd in the DNSKEY RRset for the zone, and that the NSEC / NSEC3
aaf75c27909404147cc0edb74491770e3741c195nd chains are complete.
aaf75c27909404147cc0edb74491770e3741c195nd </p>
aaf75c27909404147cc0edb74491770e3741c195nd</div>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<div class="refsect1" lang="en">
52bc21ad2115333a8295c5f3e4f328d7431e6989nd<a name="id2641148"></a><h2>OPTIONS</h2>
8f057347a12e831fdf567da83de2fa581580298dnd<div class="variablelist"><dl>
8f057347a12e831fdf567da83de2fa581580298dnd<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
8f057347a12e831fdf567da83de2fa581580298dnd<dd><p>
8f057347a12e831fdf567da83de2fa581580298dnd Specifies the DNS class of the zone.
5690d2f46bf6dedb53d41f888e290df0526f32b1kess </p></dd>
636231328a7e1ed47b4d90d08eb9085ae5f8878end<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<dd>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<p>
a7f09af958b9b0cd7e3d90a63ede010e7238d4f1nd Specifies the cryptographic hardware to use, when applicable.
5690d2f46bf6dedb53d41f888e290df0526f32b1kess </p>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<p>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess When BIND is built with OpenSSL PKCS#11 support, this defaults
5690d2f46bf6dedb53d41f888e290df0526f32b1kess to the string "pkcs11", which identifies an OpenSSL engine
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd that can drive a cryptographic accelerator or hardware service
5690d2f46bf6dedb53d41f888e290df0526f32b1kess module. When BIND is built with native PKCS#11 cryptography
b70358817fe7029e5db15756b7c26ac6b04a6904kess (--enable-native-pkcs11), it defaults to the path of the PKCS#11
5690d2f46bf6dedb53d41f888e290df0526f32b1kess provider library specified via "--with-pkcs11".
5690d2f46bf6dedb53d41f888e290df0526f32b1kess </p>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess</dd>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess<dd><p>
5690d2f46bf6dedb53d41f888e290df0526f32b1kess The format of the input zone file.
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd Possible formats are <span><strong class="command">"text"</strong></span> (default)
5690d2f46bf6dedb53d41f888e290df0526f32b1kess and <span><strong class="command">"raw"</strong></span>.
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd This option is primarily intended to be used for dynamic
1352ae75e07a97c6a9105c00dee5e09336d40eddnd signed zones so that the dumped zone file in a non-text
1352ae75e07a97c6a9105c00dee5e09336d40eddnd format containing updates can be verified independently.
8f057347a12e831fdf567da83de2fa581580298dnd The use of this option does not make much sense for
8f057347a12e831fdf567da83de2fa581580298dnd non-dynamic zones.
9294268d4d5ac750389453cca2639520a05df6d2kess </p></dd>
8f057347a12e831fdf567da83de2fa581580298dnd<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
9294268d4d5ac750389453cca2639520a05df6d2kess<dd><p>
9294268d4d5ac750389453cca2639520a05df6d2kess The zone origin. If not specified, the name of the zone file
5690d2f46bf6dedb53d41f888e290df0526f32b1kess is assumed to be the origin.
0a5a376b4b2a062a845527d3709604b1ef0f55e5kess </p></dd>
9294268d4d5ac750389453cca2639520a05df6d2kess<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
9294268d4d5ac750389453cca2639520a05df6d2kess<dd><p>
9294268d4d5ac750389453cca2639520a05df6d2kess Sets the debugging level.
5690d2f46bf6dedb53d41f888e290df0526f32b1kess </p></dd>
8f057347a12e831fdf567da83de2fa581580298dnd<dt><span class="term">-V</span></dt>
8f057347a12e831fdf567da83de2fa581580298dnd<dd><p>
aaf75c27909404147cc0edb74491770e3741c195nd Prints version information.
aaf75c27909404147cc0edb74491770e3741c195nd </p></dd>
aaf75c27909404147cc0edb74491770e3741c195nd<dt><span class="term">-x</span></dt>
aaf75c27909404147cc0edb74491770e3741c195nd<dd><p>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd Only verify that the DNSKEY RRset is signed with key-signing
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd keys. Without this flag, it is assumed that the DNSKEY RRset
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd will be signed by all active keys. When this flag is set,
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd it will not be an error if the DNSKEY RRset is not signed
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd by zone-signing keys. This corresponds to the <code class="option">-x</code>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd option in <span><strong class="command">dnssec-signzone</strong></span>.
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd </p></dd>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<dt><span class="term">-z</span></dt>
aaf75c27909404147cc0edb74491770e3741c195nd<dd>
aaf75c27909404147cc0edb74491770e3741c195nd<p>
8f057347a12e831fdf567da83de2fa581580298dnd Ignore the KSK flag on the keys when determining whether
8f057347a12e831fdf567da83de2fa581580298dnd the zone if correctly signed. Without this flag it is
8f057347a12e831fdf567da83de2fa581580298dnd assumed that there will be a non-revoked, self-signed
8f057347a12e831fdf567da83de2fa581580298dnd DNSKEY with the KSK flag set for each algorithm and
5690d2f46bf6dedb53d41f888e290df0526f32b1kess that RRsets other than DNSKEY RRset will be signed with
5690d2f46bf6dedb53d41f888e290df0526f32b1kess a different DNSKEY without the KSK flag set.
5690d2f46bf6dedb53d41f888e290df0526f32b1kess </p>
9534272616b71aaea50aeec4162e749a96aebd7fsf<p>
9534272616b71aaea50aeec4162e749a96aebd7fsf With this flag set, we only require that for each algorithm,
9534272616b71aaea50aeec4162e749a96aebd7fsf there will be at least one non-revoked, self-signed DNSKEY,
9534272616b71aaea50aeec4162e749a96aebd7fsf regardless of the KSK flag state, and that other RRsets
9534272616b71aaea50aeec4162e749a96aebd7fsf will be signed by a non-revoked key for the same algorithm
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd that includes the self-signed key; the same key may be used
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd for both purposes. This corresponds to the <code class="option">-z</code>
9534272616b71aaea50aeec4162e749a96aebd7fsf option in <span><strong class="command">dnssec-signzone</strong></span>.
9534272616b71aaea50aeec4162e749a96aebd7fsf </p>
9534272616b71aaea50aeec4162e749a96aebd7fsf</dd>
9534272616b71aaea50aeec4162e749a96aebd7fsf<dt><span class="term">zonefile</span></dt>
9534272616b71aaea50aeec4162e749a96aebd7fsf<dd><p>
9534272616b71aaea50aeec4162e749a96aebd7fsf The file containing the zone to be signed.
9534272616b71aaea50aeec4162e749a96aebd7fsf </p></dd>
9534272616b71aaea50aeec4162e749a96aebd7fsf</dl></div>
9534272616b71aaea50aeec4162e749a96aebd7fsf</div>
9534272616b71aaea50aeec4162e749a96aebd7fsf<div class="refsect1" lang="en">
9534272616b71aaea50aeec4162e749a96aebd7fsf<a name="id2642834"></a><h2>SEE ALSO</h2>
9534272616b71aaea50aeec4162e749a96aebd7fsf<p>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
9534272616b71aaea50aeec4162e749a96aebd7fsf <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
9534272616b71aaea50aeec4162e749a96aebd7fsf <em class="citetitle">RFC 4033</em>.
9534272616b71aaea50aeec4162e749a96aebd7fsf </p>
9534272616b71aaea50aeec4162e749a96aebd7fsf</div>
9534272616b71aaea50aeec4162e749a96aebd7fsf<div class="refsect1" lang="en">
9534272616b71aaea50aeec4162e749a96aebd7fsf<a name="id2642859"></a><h2>AUTHOR</h2>
9534272616b71aaea50aeec4162e749a96aebd7fsf<p><span class="corpauthor">Internet Systems Consortium</span>
9534272616b71aaea50aeec4162e749a96aebd7fsf </p>
9534272616b71aaea50aeec4162e749a96aebd7fsf</div>
9534272616b71aaea50aeec4162e749a96aebd7fsf</div>
9534272616b71aaea50aeec4162e749a96aebd7fsf<div class="navfooter">
9534272616b71aaea50aeec4162e749a96aebd7fsf<hr>
9534272616b71aaea50aeec4162e749a96aebd7fsf<table width="100%" summary="Navigation footer">
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<tr>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<td width="40%" align="left">
9534272616b71aaea50aeec4162e749a96aebd7fsf<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
9534272616b71aaea50aeec4162e749a96aebd7fsf<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
9534272616b71aaea50aeec4162e749a96aebd7fsf<td width="40%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
9534272616b71aaea50aeec4162e749a96aebd7fsf</td>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd</tr>
9534272616b71aaea50aeec4162e749a96aebd7fsf<tr>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<td width="40%" align="left" valign="top">
9534272616b71aaea50aeec4162e749a96aebd7fsf<span class="application">dnssec-signzone</span>�</td>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
9534272616b71aaea50aeec4162e749a96aebd7fsf<td width="40%" align="right" valign="top">�<span class="application">named-checkconf</span>
9534272616b71aaea50aeec4162e749a96aebd7fsf</td>
9534272616b71aaea50aeec4162e749a96aebd7fsf</tr>
9534272616b71aaea50aeec4162e749a96aebd7fsf</table>
9534272616b71aaea50aeec4162e749a96aebd7fsf</div>
9534272616b71aaea50aeec4162e749a96aebd7fsf<p style="text-align: center;">BIND Version 9.11</p>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd</body>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd</html>
6e78b54cb721beced83b8b775ee142ae9fbfaa38nd