United States-English |
|
|
HP-UX Reference > Ddnssec-signzone(1)BIND 9.3HP-UX 11i Version 3: February 2007 |
|
NAMEdnssec-signzone — DNSSEC zone signing tool SYNOPSISdnssec-signzone [-aghptz] [-c class] [-d directory] [-e end-time] [-f output-file] [-k key]... [-l domain] [-i interval] [-n nthreads] [-o origin] [-r randomdev] [-s start-time] [-v level] zonefile key... DESCRIPTIONdnssec-signzone is used to sign a zone. It generates NSEC and RRSIG records and produces a signed version of the zone. The security status of delegations from the signed zone (that is, whether the child zones are secure or not) is determined by the presence or absence of a keyset file for each child zone. If the zone to be signed has any secure subzones, the .signedkey files for those subzones need to be available in the current working directory used by dnssec-signzone. Optionsdnssec-signzone has the following options:
EXAMPLESThis example shows how dnssec-signzone can be used to sign the example.com zone with the DSA key that was generated in the example given in the manpage for dnssec-keygen (see dnssec-keygen(1)). The zone's keys must be in the zone. If there are keyset files associated with child zones, they must be in the current directory. $ dnssec-signzone -o example.com db.example.com Kexample.com.+003+26160 dnssec-signzone creates a file called example.com.signed, the signed version of the example.com zone. This file can then be referenced in a zone{} statement in /etc/named.conf so that it can be loaded by the name server. SEE ALSORequests for Comments (RFC): 2535, available online at http://www.rfc-editor.org/. HP-UX IP Address and Client Management Administrator's Guide, available online at http://docs.hp.com. BIND 9 Administrator Reference Manual, available from the Internet Systems Consortium at http://www.isc.org/sw/bind/arm93. |
Printable version | ||
|