trusted-keys.html revision 9bff67898d55cddfcec9ce30cc2b1bb6211ec691
1828N/A<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
1828N/A<!--
1828N/A - Copyright (C) 1999, 2000 Internet Software Consortium.
1828N/A -
1828N/A - Permission to use, copy, modify, and distribute this software for any
1828N/A - purpose with or without fee is hereby granted, provided that the above
1828N/A - copyright notice and this permission notice appear in all copies.
1828N/A -
1828N/A - THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS
1828N/A - ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES
1828N/A - OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE
1828N/A - CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL
1828N/A - DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR
1828N/A - PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS
1828N/A - ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS
1828N/A - SOFTWARE.
1828N/A-->
1828N/A
1828N/A<HTML>
1828N/A<HEAD>
1828N/A <TITLE>BIND trusted-keys Statement</TITLE>
1828N/A</HEAD>
1828N/A
1828N/A<BODY>
1828N/A<H2>BIND Configuration File Guide--<CODE>trusted-keys</CODE> Statement</H2>
1828N/A
1828N/A<HR>
1828N/A
1828N/A<A NAME="Syntax"><H3>Syntax</H3></A>
1828N/A
1828N/A<PRE>
1828N/Atrusted-keys {
1828N/A [ <VAR><A HREF="docdef.html">domain_name</A></VAR> <VAR><A HREF="docdef.html">number</A></VAR> <VAR><A HREF="docdef.html">number</A></VAR> <VAR><A HREF="docdef.html">number</A></VAR> <VAR>string</VAR>; ]
1828N/A};
1828N/A
1828N/A</PRE>
1828N/A
1828N/A<HR>
1828N/A
1828N/A<A NAME="Usage"><H3>Definition and Usage</H3></A>
1828N/A
1828N/AThe <CODE>trusted-keys</CODE>
1828N/Astatement is for use with DNSSEC-style security, originally specified
1882N/Ain RFC 2065. DNSSEC is meant to
1828N/Aprovide three distinct services: key distribution, data origin
1828N/Aauthentication, and transaction and request authentication. A
1828N/Acomplete description of DNSSEC and its use is beyond the scope of this
1828N/Adocument, and readers interested in more information should start with
1828N/A<A HREF="http://info.internet.isi.edu/in-notes/rfc/files/rfc2065.txt">
1882N/ARFC 2065</A> and then continue with the
1828N/A<A HREF="http://www.ietf.org/ids.by.wg/dnssec.html">
1828N/AInternet Drafts</A>.</P>
1828N/A
1828N/A<P>Each trusted key is associated with a domain name. Its attributes are
1828N/Athe non-negative integral <VAR>flags</VAR>, <VAR>protocol</VAR>, and
1828N/A<VAR>algorithm</VAR>, as well as a base-64 encoded string representing
1828N/Athe key.</P>
1828N/A
1828N/AA trusted key is added when a public key for a non-authoritative zone is
1828N/Aknown, but cannot be securely obtained through DNS. This occurs when
1828N/Aa signed zone is a child of an unsigned zone. Adding the trusted
1828N/Akey here allows data signed by that zone to be considered secure.</P>
1828N/A
1882N/A<HR>
1882N/A
1882N/A<CENTER><P>[ <A HREF="config.html">BIND Config. File</A>
1882N/A| <A HREF="http://www.vix.com/isc/bind.html">BIND Home</A>
1882N/A| <A HREF="http://www.isc.org">ISC</A> ]</P></CENTER>
1882N/A
1882N/A<HR>
1882N/A<ADDRESS>
1882N/ALast Updated: $Id: trusted-keys.html,v 1.2 2000/06/21 23:50:41 tale Exp $
1882N/A</ADDRESS>
1882N/A</BODY>
1882N/A</HTML>
1882N/A