|
NAMEdnssec-dsfromkey - DNSSEC DS RR generation toolSYNOPSISdnssec-dsfromkey [ -1 | -2 | -a alg ] [ -C ] [-T TTL] [-v level] [-K directory] {keyfile}dnssec-dsfromkey [ -1 | -2 | -a alg ] [ -C ] [-T TTL] [-v level] [-c class] [-A] {-f file} [dnsname] dnssec-dsfromkey [ -1 | -2 | -a alg ] [ -C ] [-T TTL] [-v level] [-c class] [-K directory] {-s} {dnsname} dnssec-dsfromkey [ -h | -V ] DESCRIPTIONThe dnssec-dsfromkey command outputs DS (Delegation Signer) resource records (RRs), or CDS (Child DS) RRs with the -C option.By default, only KSKs are converted (keys with flags = 257). The -A option includes ZSKs (flags = 256). Revoked keys are never included. The input keys can be specified in a number of ways: By default, dnssec-dsfromkey reads a key file named in the format Knnnn.+aaa+iiiii.key, as generated by dnssec-keygen. With the -f file option, dnssec-dsfromkey reads keys from a zone file or partial zone file (which can contain just the DNSKEY records). With the -s option, dnssec-dsfromkey reads a keyset- file, as generated by dnssec-keygen -C. OPTIONS
EXAMPLETo build the SHA-256 DS RR from the Kexample.com.+003+26160 keyfile, issue the following command:dnssec-dsfromkey -2 Kexample.com.+003+26160 The command returns something similar to: example.com. IN DS 26160 5 2 3A1EADA7A74B8D0BA86726B0C227AA85AB8BBD2B2004F41A868A54F0C5EA0B94 FILESThe keyfile can be designated by the key identification Knnnn.+aaa+iiiii or the full file name Knnnn.+aaa+iiiii.key, as generated by dnssec-keygen.The keyset file name is built from the directory, the string keyset-, and the dnsname. CAVEATA keyfile error may return "file not found," even if the file exists.SEE ALSOdnssec-keygen(8), dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 3658 (DS RRs), RFC 4509 (SHA-256 for DS RRs), RFC 6605 (SHA-384 for DS RRs), RFC 7344 (CDS and CDNSKEY RRs).AUTHORInternet Systems ConsortiumCOPYRIGHT2022, Internet Systems Consortium
Visit the GSP FreeBSD Man Page Interface. |