man.dnssec-verify.html revision 665a24faf6b3711e4012ac02ae5f0981c093ac1e
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<!--
495591bf3af0f60bc7359c69413789a24ca19411Michael Graff - Copyright (C) 2004-2014 Internet Systems Consortium, Inc. ("ISC")
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - Copyright (C) 2000-2003 Internet Software Consortium.
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff -
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - Permission to use, copy, modify, and/or distribute this software for any
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - purpose with or without fee is hereby granted, provided that the above
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - copyright notice and this permission notice appear in all copies.
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff -
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff - PERFORMANCE OF THIS SOFTWARE.
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff-->
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<!-- $Id$ -->
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<html>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<head>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<title>dnssec-verify</title>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<link rel="prev" href="man.dnssec-signzone.html" title="dnssec-signzone">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<link rel="next" href="man.named-checkconf.html" title="named-checkconf">
057393025c3c7fa2176d3d162ebdcad651d2903fMichael Graff</head>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="navheader">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<table width="100%" summary="Navigation header">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<tr><th colspan="3" align="center"><span class="application">dnssec-verify</span></th></tr>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<tr>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<td width="20%" align="left">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<th width="60%" align="center">Manual pages</th>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<td width="20%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</td>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</tr>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</table>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<hr>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refentry" lang="en">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a name="man.dnssec-verify"></a><div class="titlepage"></div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refnamediv">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<h2>Name</h2>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<p><span class="application">dnssec-verify</span> &#8212; DNSSEC zone verification tool</p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refsynopsisdiv">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<h2>Synopsis</h2>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="cmdsynopsis"><p><code class="command">dnssec-verify</code> [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-E <em class="replaceable"><code>engine</code></em></code>] [<code class="option">-I <em class="replaceable"><code>input-format</code></em></code>] [<code class="option">-o <em class="replaceable"><code>origin</code></em></code>] [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-x</code>] [<code class="option">-z</code>] {zonefile}</p></div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refsect1" lang="en">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a name="id2635873"></a><h2>DESCRIPTION</h2>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<p><span><strong class="command">dnssec-verify</strong></span>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff verifies that a zone is fully signed for each algorithm found
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff in the DNSKEY RRset for the zone, and that the NSEC / NSEC3
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff chains are complete.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff </p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refsect1" lang="en">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a name="id2635886"></a><h2>OPTIONS</h2>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="variablelist"><dl>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dd><p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff Specifies the DNS class of the zone.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff </p></dd>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dt><span class="term">-E <em class="replaceable"><code>engine</code></em></span></dt>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dd>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff Specifies the cryptographic hardware to use, when applicable.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff </p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff When BIND is built with OpenSSL PKCS#11 support, this defaults
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff to the string "pkcs11", which identifies an OpenSSL engine
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff that can drive a cryptographic accelerator or hardware service
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff module. When BIND is built with native PKCS#11 cryptography
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff (--enable-native-pkcs11), it defaults to the path of the PKCS#11
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff provider library specified via "--with-pkcs11".
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff </p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</dd>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dt><span class="term">-I <em class="replaceable"><code>input-format</code></em></span></dt>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dd><p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff The format of the input zone file.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff Possible formats are <span><strong class="command">"text"</strong></span> (default)
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff and <span><strong class="command">"raw"</strong></span>.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff This option is primarily intended to be used for dynamic
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff signed zones so that the dumped zone file in a non-text
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff format containing updates can be verified independently.
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff The use of this option does not make much sense for
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff non-dynamic zones.
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff </p></dd>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff<dt><span class="term">-o <em class="replaceable"><code>origin</code></em></span></dt>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff<dd><p>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff The zone origin. If not specified, the name of the zone file
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff is assumed to be the origin.
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff </p></dd>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<dd><p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff Sets the debugging level.
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff </p></dd>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dt><span class="term">-x</span></dt>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<dd><p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff Only verify that the DNSKEY RRset is signed with key-signing
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff keys. Without this flag, it is assumed that the DNSKEY RRset
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff will be signed by all active keys. When this flag is set,
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff it will not be an error if the DNSKEY RRset is not signed
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff by zone-signing keys. This corresponds to the <code class="option">-x</code>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff option in <span><strong class="command">dnssec-signzone</strong></span>.
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff </p></dd>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff<dt><span class="term">-z</span></dt>
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff<dd>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff<p>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff Ignore the KSK flag on the keys when determining whether
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff the zone if correctly signed. Without this flag it is
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff assumed that there will be a non-revoked, self-signed
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff DNSKEY with the KSK flag set for each algorithm and
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff that RRsets other than DNSKEY RRset will be signed with
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff a different DNSKEY without the KSK flag set.
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff </p>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<p>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff With this flag set, we only require that for each algorithm,
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff there will be at least one non-revoked, self-signed DNSKEY,
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff regardless of the KSK flag state, and that other RRsets
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff will be signed by a non-revoked key for the same algorithm
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff that includes the self-signed key; the same key may be used
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff for both purposes. This corresponds to the <code class="option">-z</code>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff option in <span><strong class="command">dnssec-signzone</strong></span>.
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff </p>
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff</dd>
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff<dt><span class="term">zonefile</span></dt>
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff<dd><p>
3b248999e6246309a6685b18903e78f97136ddbaMichael Graff The file containing the zone to be signed.
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff </p></dd>
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff</dl></div>
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refsect1" lang="en">
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<a name="id2636261"></a><h2>SEE ALSO</h2>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff<p>
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
43236eb0e13a64c84bb5e2a902fbf1411b487d36Michael Graff <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff <em class="citetitle">RFC 4033</em>.
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff </p>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<div class="refsect1" lang="en">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a name="id2636286"></a><h2>AUTHOR</h2>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<p><span class="corpauthor">Internet Systems Consortium</span>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff </p>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</div>
01086ae94328f8aec08c2b5d5b850fdc2315dbb3Michael Graff</div>
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff<div class="navfooter">
123d63ebb2b05606f8d25baaf1c31414bdfc4b7eMichael Graff<hr>
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff<table width="100%" summary="Navigation footer">
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff<tr>
7dbf5a0b64237aa3052f04f4c8f7d56be8ec5d79Michael Graff<td width="40%" align="left">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<a accesskey="p" href="man.dnssec-signzone.html">Prev</a>�</td>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<td width="40%" align="right">�<a accesskey="n" href="man.named-checkconf.html">Next</a>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff</td>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff</tr>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<tr>
57cd0c8166f0e350a21a600eb27e600a7f2c9c7fMichael Graff<td width="40%" align="left" valign="top">
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff<span class="application">dnssec-signzone</span>�</td>
658db10162f779c8a5ed4e40c77111a7e18492beMichael Graff<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
c05e003dce672b2f8555a3e56857f29ce89c1677Michael Graff<td width="40%" align="right" valign="top">�<span class="application">named-checkconf</span>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</td>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</tr>
658db10162f779c8a5ed4e40c77111a7e18492beMichael Graff</table>
c05e003dce672b2f8555a3e56857f29ce89c1677Michael Graff</div>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</body>
64bed6c54393c2d213db83e9b171fb7c318cfc8eMichael Graff</html>
c05e003dce672b2f8555a3e56857f29ce89c1677Michael Graff