dnssec-signzone.8
来自「非常好的dns解析软件」· 8 代码 · 共 258 行
8
258 行
.\" Copyright (C) 2004-2007 Internet Systems Consortium, Inc. ("ISC").\" Copyright (C) 2000-2003 Internet Software Consortium..\" .\" Permission to use, copy, modify, and distribute this software for any.\" purpose with or without fee is hereby granted, provided that the above.\" copyright notice and this permission notice appear in all copies..\" .\" THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH.\" REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY.\" AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,.\" INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM.\" LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE.\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR.\" PERFORMANCE OF THIS SOFTWARE..\".\" $Id: dnssec-signzone.8,v 1.28.18.16 2007/01/30 00:23:44 marka Exp $.\".hy 0.ad l.\" Title: dnssec\-signzone.\" Author: .\" Generator: DocBook XSL Stylesheets v1.71.1 <http://docbook.sf.net/>.\" Date: June 30, 2000.\" Manual: BIND9.\" Source: BIND9.\".TH "DNSSEC\-SIGNZONE" "8" "June 30, 2000" "BIND9" "BIND9".\" disable hyphenation.nh.\" disable justification (adjust text to left margin only).ad l.SH "NAME"dnssec\-signzone \- DNSSEC zone signing tool.SH "SYNOPSIS".HP 16\fBdnssec\-signzone\fR [\fB\-a\fR] [\fB\-c\ \fR\fB\fIclass\fR\fR] [\fB\-d\ \fR\fB\fIdirectory\fR\fR] [\fB\-e\ \fR\fB\fIend\-time\fR\fR] [\fB\-f\ \fR\fB\fIoutput\-file\fR\fR] [\fB\-g\fR] [\fB\-h\fR] [\fB\-k\ \fR\fB\fIkey\fR\fR] [\fB\-l\ \fR\fB\fIdomain\fR\fR] [\fB\-i\ \fR\fB\fIinterval\fR\fR] [\fB\-I\ \fR\fB\fIinput\-format\fR\fR] [\fB\-j\ \fR\fB\fIjitter\fR\fR] [\fB\-N\ \fR\fB\fIsoa\-serial\-format\fR\fR] [\fB\-o\ \fR\fB\fIorigin\fR\fR] [\fB\-O\ \fR\fB\fIoutput\-format\fR\fR] [\fB\-p\fR] [\fB\-r\ \fR\fB\fIrandomdev\fR\fR] [\fB\-s\ \fR\fB\fIstart\-time\fR\fR] [\fB\-t\fR] [\fB\-v\ \fR\fB\fIlevel\fR\fR] [\fB\-z\fR] {zonefile} [key...].SH "DESCRIPTION".PP\fBdnssec\-signzone\fRsigns a zone. It generates NSEC and RRSIG records and produces a signed version of the zone. The security status of delegations from the signed zone (that is, whether the child zones are secure or not) is determined by the presence or absence of a\fIkeyset\fRfile for each child zone..SH "OPTIONS".PP\-a.RS 4Verify all generated signatures..RE.PP\-c \fIclass\fR.RS 4Specifies the DNS class of the zone..RE.PP\-k \fIkey\fR.RS 4Treat specified key as a key signing key ignoring any key flags. This option may be specified multiple times..RE.PP\-l \fIdomain\fR.RS 4Generate a DLV set in addition to the key (DNSKEY) and DS sets. The domain is appended to the name of the records..RE.PP\-d \fIdirectory\fR.RS 4Look for\fIkeyset\fRfiles in\fBdirectory\fRas the directory.RE.PP\-g.RS 4Generate DS records for child zones from keyset files. Existing DS records will be removed..RE.PP\-s \fIstart\-time\fR.RS 4Specify the date and time when the generated RRSIG records become valid. This can be either an absolute or relative time. An absolute start time is indicated by a number in YYYYMMDDHHMMSS notation; 20000530144500 denotes 14:45:00 UTC on May 30th, 2000. A relative start time is indicated by +N, which is N seconds from the current time. If no\fBstart\-time\fRis specified, the current time minus 1 hour (to allow for clock skew) is used..RE.PP\-e \fIend\-time\fR.RS 4Specify the date and time when the generated RRSIG records expire. As with\fBstart\-time\fR, an absolute time is indicated in YYYYMMDDHHMMSS notation. A time relative to the start time is indicated with +N, which is N seconds from the start time. A time relative to the current time is indicated with now+N. If no\fBend\-time\fRis specified, 30 days from the start time is used as a default..RE.PP\-f \fIoutput\-file\fR.RS 4The name of the output file containing the signed zone. The default is to append\fI.signed\fRto the input file..RE.PP\-h.RS 4Prints a short summary of the options and arguments to\fBdnssec\-signzone\fR..RE.PP\-i \fIinterval\fR.RS 4When a previously signed zone is passed as input, records may be resigned. The\fBinterval\fRoption specifies the cycle interval as an offset from the current time (in seconds). If a RRSIG record expires after the cycle interval, it is retained. Otherwise, it is considered to be expiring soon, and it will be replaced..spThe default cycle interval is one quarter of the difference between the signature end and start times. So if neither\fBend\-time\fRor\fBstart\-time\fRare specified,\fBdnssec\-signzone\fRgenerates signatures that are valid for 30 days, with a cycle interval of 7.5 days. Therefore, if any existing RRSIG records are due to expire in less than 7.5 days, they would be replaced..RE.PP\-I \fIinput\-format\fR.RS 4The format of the input zone file. Possible formats are\fB"text"\fR(default) and\fB"raw"\fR. This option is primarily intended to be used for dynamic signed zones so that the dumped zone file in a non\-text format containing updates can be signed directly. The use of this option does not make much sense for non\-dynamic zones..RE.PP\-j \fIjitter\fR.RS 4When signing a zone with a fixed signature lifetime, all RRSIG records issued at the time of signing expires simultaneously. If the zone is incrementally signed, i.e. a previously signed zone is passed as input to the signer, all expired signatures has to be regenerated at about the same time. The\fBjitter\fRoption specifies a jitter window that will be used to randomize the signature expire time, thus spreading incremental signature regeneration over time..spSignature lifetime jitter also to some extent benefits validators and servers by spreading out cache expiration, i.e. if large numbers of RRSIGs don't expire at the same time from all caches there will be less congestion than if all validators need to refetch at mostly the same time..RE.PP\-n \fIncpus\fR.RS 4Specifies the number of threads to use. By default, one thread is started for each detected CPU..RE.PP\-N \fIsoa\-serial\-format\fR.RS 4The SOA serial number format of the signed zone. Possible formats are\fB"keep"\fR(default),\fB"increment"\fRand\fB"unixtime"\fR..RS 4.PP\fB"keep"\fR.RS 4Do not modify the SOA serial number..RE.PP\fB"increment"\fR.RS 4Increment the SOA serial number using RFC 1982 arithmetics..RE.PP\fB"unixtime"\fR.RS 4Set the SOA serial number to the number of seconds since epoch..RE.RE.RE.PP\-o \fIorigin\fR.RS 4The zone origin. If not specified, the name of the zone file is assumed to be the origin..RE.PP\-O \fIoutput\-format\fR.RS 4The format of the output file containing the signed zone. Possible formats are\fB"text"\fR(default) and\fB"raw"\fR..RE.PP\-p.RS 4Use pseudo\-random data when signing the zone. This is faster, but less secure, than using real random data. This option may be useful when signing large zones or when the entropy source is limited..RE.PP\-r \fIrandomdev\fR.RS 4Specifies the source of randomness. If the operating system does not provide a\fI/dev/random\fRor equivalent device, the default source of randomness is keyboard input.\fIrandomdev\fRspecifies the name of a character device or file containing random data to be used instead of the default. The special value\fIkeyboard\fRindicates that keyboard input should be used..RE.PP\-t.RS 4Print statistics at completion..RE.PP\-v \fIlevel\fR.RS 4Sets the debugging level..RE.PP\-z.RS 4Ignore KSK flag on key when determining what to sign..RE.PPzonefile.RS 4The file containing the zone to be signed..RE.PPkey.RS 4The keys used to sign the zone. If no keys are specified, the default all zone keys that have private key files in the current directory..RE.SH "EXAMPLE".PPThe following command signs the\fBexample.com\fRzone with the DSA key generated in the\fBdnssec\-keygen\fRman page. The zone's keys must be in the zone. If there are\fIkeyset\fRfiles associated with child zones, they must be in the current directory.\fBexample.com\fR, the following command would be issued:.PP\fBdnssec\-signzone \-o example.com db.example.com Kexample.com.+003+26160\fR.PPThe command would print a string of the form:.PPIn this example,\fBdnssec\-signzone\fRcreates the file\fIdb.example.com.signed\fR. This file should be referenced in a zone statement in a\fInamed.conf\fRfile..SH "SEE ALSO".PP\fBdnssec\-keygen\fR(8),BIND 9 Administrator Reference Manual,RFC 2535..SH "AUTHOR".PPInternet Systems Consortium.SH "COPYRIGHT"Copyright \(co 2004\-2007 Internet Systems Consortium, Inc. ("ISC").brCopyright \(co 2000\-2003 Internet Software Consortium..br
⌨️ 快捷键说明
复制代码Ctrl + C
搜索代码Ctrl + F
全屏模式F11
增大字号Ctrl + =
减小字号Ctrl + -
显示快捷键?