/usr/share/doc/bind
NameSizeModeActions
sample/-0755rm
Bv9ARM.ch01.html271680644editdlrm
Bv9ARM.ch02.html71600644editdlrm
Bv9ARM.ch03.html286990644editdlrm
Bv9ARM.ch04.html1293840644editdlrm
Bv9ARM.ch05.html61650644editdlrm
Bv9ARM.ch06.html6676440644editdlrm
Bv9ARM.ch07.html194930644editdlrm
Bv9ARM.ch08.html61400644editdlrm
Bv9ARM.ch09.html1198350644editdlrm
Bv9ARM.ch10.html71510644editdlrm
Bv9ARM.ch11.html452770644editdlrm
Bv9ARM.ch12.html201360644editdlrm
Bv9ARM.ch13.html98990644editdlrm
Bv9ARM.html338550644editdlrm
Bv9ARM.pdf11278330644editdlrm
CHANGES5737570644editdlrm
isc-logo.pdf171890644editdlrm
man.arpaname.html29540644editdlrm
man.ddns-confgen.html93640644editdlrm
man.delv.html238080644editdlrm
man.dig.html422780644editdlrm
man.dnssec-checkds.html51590644editdlrm
man.dnssec-coverage.html111420644editdlrm
man.dnssec-dsfromkey.html120910644editdlrm
man.dnssec-importkey.html94460644editdlrm
man.dnssec-keyfromlabel.html188600644editdlrm
man.dnssec-keygen.html224630644editdlrm
man.dnssec-keymgr.html164680644editdlrm
man.dnssec-revoke.html54490644editdlrm
man.dnssec-settime.html142440644editdlrm
man.dnssec-signzone.html298780644editdlrm
man.dnssec-verify.html73020644editdlrm
man.dnstap-read.html43160644editdlrm
man.genrandom.html39530644editdlrm
man.host.html130520644editdlrm
man.isc-hmac-fixup.html45310644editdlrm
man.lwresd.html120500644editdlrm
man.mdig.html227890644editdlrm
man.named-checkconf.html65860644editdlrm
man.named-checkzone.html197100644editdlrm
man.named-journalprint.html41750644editdlrm
man.named-nzd2nzf.html38180644editdlrm
man.named-rrchecker.html41610644editdlrm
man.named.conf.html748020644editdlrm
man.named.html184450644editdlrm
man.nsec3hash.html39740644editdlrm
man.nslookup.html148920644editdlrm
man.nsupdate.html280580644editdlrm
man.pkcs11-destroy.html53920644editdlrm
man.pkcs11-keygen.html68840644editdlrm
man.pkcs11-list.html52950644editdlrm
man.pkcs11-tokens.html38510644editdlrm
man.rndc-confgen.html112860644editdlrm
man.rndc.conf.html101980644editdlrm
man.rndc.html404090644editdlrm
named.conf.default17050644editdlrm
notes.html1133130644editdlrm
notes.pdf1623470644editdlrm
README284950644editdlrm
Edit: /usr/share/doc/bind/man.dnssec-importkey.html (9446B)
dnssec-importkey

Name

dnssec-importkey — import DNSKEY records from external systems so they can be managed

Synopsis

dnssec-importkey [-K directory] [-L ttl] [-P date/offset] [-P sync date/offset] [-D date/offset] [-D sync date/offset] [-h] [-v level] [-V] {keyfile}

dnssec-importkey {-f filename} [-K directory] [-L ttl] [-P date/offset] [-P sync date/offset] [-D date/offset] [-D sync date/offset] [-h] [-v level] [-V] [dnsname]

DESCRIPTION

dnssec-importkey reads a public DNSKEY record and generates a pair of .key/.private files. The DNSKEY record may be read from an existing .key file, in which case a corresponding .private file will be generated, or it may be read from any other file or from the standard input, in which case both .key and .private files will be generated.

The newly-created .private file does not contain private key data, and cannot be used for signing. However, having a .private file makes it possible to set publication (-P) and deletion (-D) times for the key, which means the public key can be added to and removed from the DNSKEY RRset on schedule even if the true private key is stored offline.

OPTIONS

-f filename

Zone file mode: instead of a public keyfile name, the argument is the DNS domain name of a zone master file, which can be read from file. If the domain name is the same as file, then it may be omitted.

If file is set to "-", then the zone data is read from the standard input.

-K directory

Sets the directory in which the key files are to reside.

-L ttl

Sets the default TTL to use for this key when it is converted into a DNSKEY RR. If the key is imported into a zone, this is the TTL that will be used for it, unless there was already a DNSKEY RRset in place, in which case the existing TTL would take precedence. Setting the default TTL to 0 or none removes it.

-h

Emit usage message and exit.

-v level

Sets the debugging level.

-V

Prints version information.

TIMING OPTIONS

Dates can be expressed in the format YYYYMMDD or YYYYMMDDHHMMSS. If the argument begins with a '+' or '-', it is interpreted as an offset from the present time. For convenience, if such an offset is followed by one of the suffixes 'y', 'mo', 'w', 'd', 'h', or 'mi', then the offset is computed in years (defined as 365 24-hour days, ignoring leap years), months (defined as 30 24-hour days), weeks, days, hours, or minutes, respectively. Without a suffix, the offset is computed in seconds. To explicitly prevent a date from being set, use 'none' or 'never'.

-P date/offset

Sets the date on which a key is to be published to the zone. After that date, the key will be included in the zone but will not be used to sign it.

-P sync date/offset

Sets the date on which CDS and CDNSKEY records that match this key are to be published to the zone.

-D date/offset

Sets the date on which the key is to be deleted. After that date, the key will no longer be included in the zone. (It may remain in the key repository, however.)

-D sync date/offset

Sets the date on which the CDS and CDNSKEY records that match this key are to be deleted.

FILES

A keyfile can be designed by the key identification Knnnn.+aaa+iiiii or the full file name Knnnn.+aaa+iiiii.key as generated by dnssec-keygen(8).

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 5011.

BIND 9.11.36 (Extended Support Version)