man.dnssec-dsfromkey.html 7.32 KB
Newer Older
1
<!--
Automatic Updater's avatar
regen  
Automatic Updater committed
2
 - Copyright (C) 2004-2009 Internet Systems Consortium, Inc. ("ISC")
Automatic Updater's avatar
regen  
Automatic Updater committed
3 4 5
 - Copyright (C) 2000-2003 Internet Software Consortium.
 - 
 - Permission to use, copy, modify, and distribute this software for any
6 7
 - purpose with or without fee is hereby granted, provided that the above
 - copyright notice and this permission notice appear in all copies.
Automatic Updater's avatar
regen  
Automatic Updater committed
8
 - 
9 10
 - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
 - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
Automatic Updater's avatar
regen  
Automatic Updater committed
11
 - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 13 14 15 16
 - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
 - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
 - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
 - PERFORMANCE OF THIS SOFTWARE.
-->
Automatic Updater's avatar
regen  
Automatic Updater committed
17
<!-- $Id: man.dnssec-dsfromkey.html,v 1.10 2009/01/09 01:11:52 tbox Exp $ -->
18 19 20 21
<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-1">
<title>dnssec-dsfromkey</title>
Automatic Updater's avatar
regen  
Automatic Updater committed
22
<meta name="generator" content="DocBook XSL Stylesheets V1.71.1">
23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53
<link rel="start" href="Bv9ARM.html" title="BIND 9 Administrator Reference Manual">
<link rel="up" href="Bv9ARM.ch10.html" title="Manual pages">
<link rel="prev" href="man.host.html" title="host">
<link rel="next" href="man.dnssec-keyfromlabel.html" title="dnssec-keyfromlabel">
</head>
<body bgcolor="white" text="black" link="#0000FF" vlink="#840084" alink="#0000FF">
<div class="navheader">
<table width="100%" summary="Navigation header">
<tr><th colspan="3" align="center"><span class="application">dnssec-dsfromkey</span></th></tr>
<tr>
<td width="20%" align="left">
<a accesskey="p" href="man.host.html">Prev</a></td>
<th width="60%" align="center">Manual pages</th>
<td width="20%" align="right"><a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
</td>
</tr>
</table>
<hr>
</div>
<div class="refentry" lang="en">
<a name="man.dnssec-dsfromkey"></a><div class="titlepage"></div>
<div class="refnamediv">
<h2>Name</h2>
<p><span class="application">dnssec-dsfromkey</span> &#8212; DNSSEC DS RR generation tool</p>
</div>
<div class="refsynopsisdiv">
<h2>Synopsis</h2>
<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code>  [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-1</code>] [<code class="option">-2</code>] [<code class="option">-a <em class="replaceable"><code>alg</code></em></code>] {keyfile}</p></div>
<div class="cmdsynopsis"><p><code class="command">dnssec-dsfromkey</code>  {-s} [<code class="option">-v <em class="replaceable"><code>level</code></em></code>] [<code class="option">-1</code>] [<code class="option">-2</code>] [<code class="option">-a <em class="replaceable"><code>alg</code></em></code>] [<code class="option">-c <em class="replaceable"><code>class</code></em></code>] [<code class="option">-d <em class="replaceable"><code>dir</code></em></code>] {dnsname}</p></div>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
54
<a name="id2603193"></a><h2>DESCRIPTION</h2>
Automatic Updater's avatar
regen  
Automatic Updater committed
55
<p><span><strong class="command">dnssec-dsfromkey</strong></span>
Automatic Updater's avatar
regen  
Automatic Updater committed
56
      outputs the Delegation Signer (DS) resource record (RR), as defined in
Automatic Updater's avatar
regen  
Automatic Updater committed
57
      RFC 3658 and RFC 4509, for the given key(s).
58 59 60
    </p>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
61
<a name="id2603207"></a><h2>OPTIONS</h2>
62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101
<div class="variablelist"><dl>
<dt><span class="term">-1</span></dt>
<dd><p>
            Use SHA-1 as the digest algorithm (the default is to use
            both SHA-1 and SHA-256).
          </p></dd>
<dt><span class="term">-2</span></dt>
<dd><p>
            Use SHA-256 as the digest algorithm.
          </p></dd>
<dt><span class="term">-a <em class="replaceable"><code>algorithm</code></em></span></dt>
<dd><p>
            Select the digest algorithm. The value of
            <code class="option">algorithm</code> must be one of SHA-1 (SHA1) or
            SHA-256 (SHA256). These values are case insensitive.
          </p></dd>
<dt><span class="term">-v <em class="replaceable"><code>level</code></em></span></dt>
<dd><p>
            Sets the debugging level.
          </p></dd>
<dt><span class="term">-s</span></dt>
<dd><p>
            Keyset mode: in place of the keyfile name, the argument is
            the DNS domain name of a keyset file. Following options make sense
            only in this mode.
          </p></dd>
<dt><span class="term">-c <em class="replaceable"><code>class</code></em></span></dt>
<dd><p>
            Specifies the DNS class (default is IN), useful only
            in the keyset mode.
          </p></dd>
<dt><span class="term">-d <em class="replaceable"><code>directory</code></em></span></dt>
<dd><p>
            Look for <code class="filename">keyset</code> files in
            <code class="option">directory</code> as the directory, ignored when
            not in the keyset mode.
          </p></dd>
</dl></div>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
102
<a name="id2603405"></a><h2>EXAMPLE</h2>
103 104 105 106 107 108 109 110 111 112 113 114 115 116
<p>
      To build the SHA-256 DS RR from the
      <strong class="userinput"><code>Kexample.com.+003+26160</code></strong>
      keyfile name, the following command would be issued:
    </p>
<p><strong class="userinput"><code>dnssec-dsfromkey -2 Kexample.com.+003+26160</code></strong>
    </p>
<p>
      The command would print something like:
    </p>
<p><strong class="userinput"><code>example.com. IN DS 26160 5 2 3A1EADA7A74B8D0BA86726B0C227AA85AB8BBD2B2004F41A868A54F0 C5EA0B94</code></strong>
    </p>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
117
<a name="id2603442"></a><h2>FILES</h2>
118 119 120
<p>
      The keyfile can be designed by the key identification
      <code class="filename">Knnnn.+aaa+iiiii</code> or the full file name
Automatic Updater's avatar
regen  
Automatic Updater committed
121
      <code class="filename">Knnnn.+aaa+iiiii.key</code> as generated by
Automatic Updater's avatar
regen  
Automatic Updater committed
122
      <span class="refentrytitle">dnssec-keygen</span>(8).
123 124 125 126 127 128 129 130
    </p>
<p>
      The keyset file name is built from the <code class="option">directory</code>,
      the string <code class="filename">keyset-</code> and the
      <code class="option">dnsname</code>.
    </p>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
131
<a name="id2603483"></a><h2>CAVEAT</h2>
132 133 134 135 136
<p>
      A keyfile error can give a "file not found" even if the file exists.
    </p>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
137
<a name="id2603493"></a><h2>SEE ALSO</h2>
138 139 140 141 142 143 144 145
<p><span class="citerefentry"><span class="refentrytitle">dnssec-keygen</span>(8)</span>,
      <span class="citerefentry"><span class="refentrytitle">dnssec-signzone</span>(8)</span>,
      <em class="citetitle">BIND 9 Administrator Reference Manual</em>,
      <em class="citetitle">RFC 3658</em>,
      <em class="citetitle">RFC 4509</em>.
    </p>
</div>
<div class="refsect1" lang="en">
Automatic Updater's avatar
regen  
Automatic Updater committed
146
<a name="id2603529"></a><h2>AUTHOR</h2>
147 148 149 150 151 152 153 154 155 156 157 158 159 160 161
<p><span class="corpauthor">Internet Systems Consortium</span>
    </p>
</div>
</div>
<div class="navfooter">
<hr>
<table width="100%" summary="Navigation footer">
<tr>
<td width="40%" align="left">
<a accesskey="p" href="man.host.html">Prev</a></td>
<td width="20%" align="center"><a accesskey="u" href="Bv9ARM.ch10.html">Up</a></td>
<td width="40%" align="right"><a accesskey="n" href="man.dnssec-keyfromlabel.html">Next</a>
</td>
</tr>
<tr>
Automatic Updater's avatar
regen  
Automatic Updater committed
162
<td width="40%" align="left" valign="top">host</td>
163 164 165 166 167 168 169
<td width="20%" align="center"><a accesskey="h" href="Bv9ARM.html">Home</a></td>
<td width="40%" align="right" valign="top"><span class="application">dnssec-keyfromlabel</span>
</td>
</tr>
</table>
</div>
</body>
Automatic Updater's avatar
regen  
Automatic Updater committed
170
</html>