1828N/A<!
DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
1828N/A - Copyright (C) 1999, 2000 Internet Software Consortium. 1828N/A - Permission to use, copy, modify, and distribute this software for any 1828N/A - purpose with or without fee is hereby granted, provided that the above 1828N/A - copyright notice and this permission notice appear in all copies. 1828N/A - THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM DISCLAIMS 1828N/A - ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES 1828N/A - OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL INTERNET SOFTWARE 1828N/A - CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL 1828N/A - DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR 1828N/A - PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS 1828N/A - ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS 1828N/A <
TITLE>BIND trusted-keys Statement</
TITLE>
1828N/A<
H2>BIND Configuration File Guide--<
CODE>trusted-keys</
CODE> Statement</
H2>
1828N/A<
A NAME="Syntax"><
H3>Syntax</
H3></
A>
1828N/A<
A NAME="Usage"><
H3>Definition and Usage</
H3></
A>
1828N/AThe <
CODE>trusted-keys</
CODE>
1828N/Astatement is for use with DNSSEC-style security, originally specified
1882N/Ain RFC 2065. DNSSEC is meant to
1828N/Aprovide three distinct services: key distribution, data origin
1828N/Aauthentication, and transaction and request authentication. A
1828N/Acomplete description of DNSSEC and its use is beyond the scope of this
1828N/Adocument, and readers interested in more information should start with
1882N/ARFC 2065</
A> and then continue with the
1828N/A<
P>Each trusted key is associated with a domain name. Its attributes are
1828N/Athe non-negative integral <
VAR>flags</
VAR>, <
VAR>protocol</
VAR>, and
1828N/A<
VAR>algorithm</
VAR>, as well as a base-64 encoded string representing
1828N/AA trusted key is added when a public key for a non-authoritative zone is
1828N/Aknown, but cannot be securely obtained through DNS. This occurs when
1828N/Aa signed zone is a child of an unsigned zone. Adding the trusted
1828N/Akey here allows data signed by that zone to be considered secure.</
P>