|
NAMEzkt-conf — Secure DNS zone key config toolSYNOPSYSzkt-conf [-V name] [-w] -d [-O optstr]zkt-conf [-V name] [-w] [-s] [-c file] [-O optstr] zkt-conf [-V name] [-w] -l [-a] [-c file] [-O optstr] zkt-conf [-c file] [-w] zonefile DESCRIPTIONThe zkt-conf command helps to create and show a config file for use by the Zone Key Tool commands, which are currently zkt-ls(8) , zkt-keyman(8) , and zkt-signer(8).In general, the ZKT commands uses up to three consequitive sources for config parameter settings:
Because of the overload feature, none of the config files has to have a complete parameter set. Typically the local config file will have only those parameters which are different from the global or built-in ones. The default operation of zkt-conf(8) is to print the site wide config file (same as option -s). Option -d will print out the built-in defaults while -l print those local parameters which are different to the global ones. In the last case -a gives the fully (--all) parameter list. In all forms of the command, the parameters are changeable via option -O (--config-option). With option -w (--write) the confg parameters are written back to the config file. This is useful in case of an ZKT upgrade or if one or more parameters are changed by option -O. Option -t checks some of the parameter for reasonable values. Which config file is shown (or modified or checked) is determined by an option. -d means the built-in defaults, option -l is for the local config file and -s specifies the site wide config file. Option -s is the default. In the last form of the command, the maximum TTL value of all the resource records of zonefile is calculated and print on stdout. Additional, the zonefile is checked if the key database (dnskey.db) is included in the zone file. If option -w is set, than the INCLUDE directive will be added to the zone file if necessary, and the maximum ttl value is written to a local config file. COMMAND OPTIONS
OPTIONS
SAMPLE USAGE
ENVIRONMENT VARIABLES
FILES
AUTHORSHolger ZulegerCOPYRIGHTCopyright (c) 2005 - 2010 by Holger Zuleger. Licensed under the BSD Licences. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.SEE ALSOdnssec-keygen(8), dnssec-signzone(8), rndc(8), named.conf(5), zkt-signer(8), zkt-ls(8), zkt-keyman(8),RFC4641 "DNSSEC Operational Practices" by Miek Gieben and Olaf Kolkman, DNSSEC HOWTO Tutorial by Olaf Kolkman, RIPE NCC (http://www.nlnetlabs.nl/dnssec_howto/)
Visit the GSP FreeBSD Man Page Interface. |