diff options
Diffstat (limited to 'contrib/bind9/bin/dnssec/dnssec-dsfromkey.docbook')
-rw-r--r-- | contrib/bind9/bin/dnssec/dnssec-dsfromkey.docbook | 279 |
1 files changed, 0 insertions, 279 deletions
diff --git a/contrib/bind9/bin/dnssec/dnssec-dsfromkey.docbook b/contrib/bind9/bin/dnssec/dnssec-dsfromkey.docbook deleted file mode 100644 index 77c0994..0000000 --- a/contrib/bind9/bin/dnssec/dnssec-dsfromkey.docbook +++ /dev/null @@ -1,279 +0,0 @@ -<!DOCTYPE book PUBLIC "-//OASIS//DTD DocBook XML V4.2//EN" - "http://www.oasis-open.org/docbook/xml/4.2/docbookx.dtd" - [<!ENTITY mdash "—">]> -<!-- - - Copyright (C) 2008-2012 Internet Systems Consortium, Inc. ("ISC") - - - - Permission to use, copy, modify, and/or distribute this software for any - - purpose with or without fee is hereby granted, provided that the above - - copyright notice and this permission notice appear in all copies. - - - - THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH - - REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY - - AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT, - - INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM - - LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE - - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - - PERFORMANCE OF THIS SOFTWARE. ---> - -<!-- $Id: dnssec-dsfromkey.docbook,v 1.17 2011/10/25 01:54:18 marka Exp $ --> -<refentry id="man.dnssec-dsfromkey"> - <refentryinfo> - <date>August 26, 2009</date> - </refentryinfo> - - <refmeta> - <refentrytitle><application>dnssec-dsfromkey</application></refentrytitle> - <manvolnum>8</manvolnum> - <refmiscinfo>BIND9</refmiscinfo> - </refmeta> - - <refnamediv> - <refname><application>dnssec-dsfromkey</application></refname> - <refpurpose>DNSSEC DS RR generation tool</refpurpose> - </refnamediv> - - <docinfo> - <copyright> - <year>2008</year> - <year>2009</year> - <year>2010</year> - <year>2011</year> - <year>2012</year> - <holder>Internet Systems Consortium, Inc. ("ISC")</holder> - </copyright> - </docinfo> - - <refsynopsisdiv> - <cmdsynopsis> - <command>dnssec-dsfromkey</command> - <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg> - <arg><option>-1</option></arg> - <arg><option>-2</option></arg> - <arg><option>-a <replaceable class="parameter">alg</replaceable></option></arg> - <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg> - <arg><option>-T <replaceable class="parameter">TTL</replaceable></option></arg> - <arg choice="req">keyfile</arg> - </cmdsynopsis> - <cmdsynopsis> - <command>dnssec-dsfromkey</command> - <arg choice="req">-s</arg> - <arg><option>-1</option></arg> - <arg><option>-2</option></arg> - <arg><option>-a <replaceable class="parameter">alg</replaceable></option></arg> - <arg><option>-K <replaceable class="parameter">directory</replaceable></option></arg> - <arg><option>-l <replaceable class="parameter">domain</replaceable></option></arg> - <arg><option>-s</option></arg> - <arg><option>-c <replaceable class="parameter">class</replaceable></option></arg> - <arg><option>-T <replaceable class="parameter">TTL</replaceable></option></arg> - <arg><option>-f <replaceable class="parameter">file</replaceable></option></arg> - <arg><option>-A</option></arg> - <arg><option>-v <replaceable class="parameter">level</replaceable></option></arg> - <arg choice="req">dnsname</arg> - </cmdsynopsis> - </refsynopsisdiv> - - <refsect1> - <title>DESCRIPTION</title> - <para><command>dnssec-dsfromkey</command> - outputs the Delegation Signer (DS) resource record (RR), as defined in - RFC 3658 and RFC 4509, for the given key(s). - </para> - </refsect1> - - <refsect1> - <title>OPTIONS</title> - - <variablelist> - <varlistentry> - <term>-1</term> - <listitem> - <para> - Use SHA-1 as the digest algorithm (the default is to use - both SHA-1 and SHA-256). - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-2</term> - <listitem> - <para> - Use SHA-256 as the digest algorithm. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-a <replaceable class="parameter">algorithm</replaceable></term> - <listitem> - <para> - Select the digest algorithm. The value of - <option>algorithm</option> must be one of SHA-1 (SHA1), - SHA-256 (SHA256), GOST or SHA-384 (SHA384). - These values are case insensitive. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-T <replaceable class="parameter">TTL</replaceable></term> - <listitem> - <para> - Specifies the TTL of the DS records. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-K <replaceable class="parameter">directory</replaceable></term> - <listitem> - <para> - Look for key files (or, in keyset mode, - <filename>keyset-</filename> files) in - <option>directory</option>. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-f <replaceable class="parameter">file</replaceable></term> - <listitem> - <para> - Zone file mode: in place of the keyfile name, the argument is - the DNS domain name of a zone master file, which can be read - from <option>file</option>. If the zone name is the same as - <option>file</option>, then it may be omitted. - </para> - <para> - If <option>file</option> is set to <literal>"-"</literal>, then - the zone data is read from the standard input. This makes it - possible to use the output of the <command>dig</command> - command as input, as in: - </para> - <para> - <userinput>dig dnskey example.com | dnssec-dsfromkey -f - example.com</userinput> - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-A</term> - <listitem> - <para> - Include ZSK's when generating DS records. Without this option, - only keys which have the KSK flag set will be converted to DS - records and printed. Useful only in zone file mode. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-l <replaceable class="parameter">domain</replaceable></term> - <listitem> - <para> - Generate a DLV set instead of a DS set. The specified - <option>domain</option> is appended to the name for each - record in the set. - The DNSSEC Lookaside Validation (DLV) RR is described - in RFC 4431. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-s</term> - <listitem> - <para> - Keyset mode: in place of the keyfile name, the argument is - the DNS domain name of a keyset file. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-c <replaceable class="parameter">class</replaceable></term> - <listitem> - <para> - Specifies the DNS class (default is IN). Useful only - in keyset or zone file mode. - </para> - </listitem> - </varlistentry> - - <varlistentry> - <term>-v <replaceable class="parameter">level</replaceable></term> - <listitem> - <para> - Sets the debugging level. - </para> - </listitem> - </varlistentry> - </variablelist> - </refsect1> - - <refsect1> - <title>EXAMPLE</title> - <para> - To build the SHA-256 DS RR from the - <userinput>Kexample.com.+003+26160</userinput> - keyfile name, the following command would be issued: - </para> - <para><userinput>dnssec-dsfromkey -2 Kexample.com.+003+26160</userinput> - </para> - <para> - The command would print something like: - </para> - <para><userinput>example.com. IN DS 26160 5 2 3A1EADA7A74B8D0BA86726B0C227AA85AB8BBD2B2004F41A868A54F0 C5EA0B94</userinput> - </para> - </refsect1> - - <refsect1> - <title>FILES</title> - <para> - The keyfile can be designed by the key identification - <filename>Knnnn.+aaa+iiiii</filename> or the full file name - <filename>Knnnn.+aaa+iiiii.key</filename> as generated by - <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum>. - </para> - <para> - The keyset file name is built from the <option>directory</option>, - the string <filename>keyset-</filename> and the - <option>dnsname</option>. - </para> - </refsect1> - - <refsect1> - <title>CAVEAT</title> - <para> - A keyfile error can give a "file not found" even if the file exists. - </para> - </refsect1> - - <refsect1> - <title>SEE ALSO</title> - <para><citerefentry> - <refentrytitle>dnssec-keygen</refentrytitle><manvolnum>8</manvolnum> - </citerefentry>, - <citerefentry> - <refentrytitle>dnssec-signzone</refentrytitle><manvolnum>8</manvolnum> - </citerefentry>, - <citetitle>BIND 9 Administrator Reference Manual</citetitle>, - <citetitle>RFC 3658</citetitle>, - <citetitle>RFC 4431</citetitle>. - <citetitle>RFC 4509</citetitle>. - </para> - </refsect1> - - <refsect1> - <title>AUTHOR</title> - <para><corpauthor>Internet Systems Consortium</corpauthor> - </para> - </refsect1> - -</refentry><!-- - - Local variables: - - mode: sgml - - End: ---> |