mirror of
https://github.com/NLnetLabs/dnst.git
synced 2026-09-28 04:34:57 +02:00
* Fix sphinx default language * Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command. * Update dnst-nsec3-hash.rst * Add key2ds manual * Add dnst-keygen manual * Change dnst-keygen algorithms to list from table * Change dnst-keygen algorithms back to table * Add ldns-keygen manual * Add notify manuals * Add signzone manuals * Add subcommands to dnst manual and table of contents * Update dnst-nsec3-hash manual * Add update manual * Apply feedback * Apply further feedback * Move signzone date description into own section * Update signzone hash iterations manual text * Add Arguments sections * Add basic intro text for dnst * Fix ldns-signzone default nsec3 hash iterations * Update nse3-hash defaults and wording * Update dnst-key2ds ignore-sep and force * Update nse3-hash default to what it is currently in main --------- Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
75 lines
2.1 KiB
ReStructuredText
75 lines
2.1 KiB
ReStructuredText
dnst keygen
|
|
===============
|
|
|
|
Synopsis
|
|
--------
|
|
|
|
:program:`dnst keygen` ``[OPTIONS]`` ``-a <ALGORITHM>`` ``<DOMAIN NAME>``
|
|
|
|
Description
|
|
-----------
|
|
|
|
**dnst keygen** generates a new key pair for a given domain name.
|
|
|
|
The following files will be created:
|
|
|
|
- ``K<name>+<alg>+<tag>.key``: The public key file containing a DNSKEY RR in
|
|
zone file format.
|
|
|
|
- ``K<name>+<alg>+<tag>.private``: The private key file containing the private
|
|
key data fields in BIND's *Private-key-format*.
|
|
|
|
- ``K<name>+<alg>+<tag>.ds``: The public key digest file containing the DS RR
|
|
in zone file format. It is only created for key signing keys.
|
|
|
|
| ``<name>`` is the fully-qualified owner name for the key (with a trailing dot).
|
|
| ``<alg>`` is the algorithm number of the key, zero-padded to 3 digits.
|
|
| ``<tag>`` is the 16-bit tag of the key, zero-padded to 5 digits.
|
|
|
|
Upon completion, ``K<name>+<alg>+<tag>`` will be printed.
|
|
|
|
Options
|
|
-------
|
|
|
|
.. option:: -a <NUMBER OR MNEMONIC>
|
|
|
|
Use the given signing algorithm.
|
|
|
|
Possible values are:
|
|
|
|
=================== ========== =========================
|
|
**Mnemonic** **Number** **Description**
|
|
=================== ========== =========================
|
|
``list`` List available algorithms
|
|
``RSASHA256`` 8 RSA with SHA-256
|
|
``ECDSAP256SHA256`` 13 ECDSA P-256 with SHA-256
|
|
``ECDSAP384SHA384`` 14 ECDSA P-384 with SHA-384
|
|
``ED25519`` 15 ED25519
|
|
``ED448`` 16 ED448
|
|
=================== ========== =========================
|
|
|
|
.. option:: -k
|
|
|
|
Generate a key signing key (KSK) instead of a zone signing key (ZSK).
|
|
|
|
.. option:: -b <BITS>
|
|
|
|
The length of the key (for RSA keys only). Defaults to 2048.
|
|
|
|
.. option:: -r <DEVICE>
|
|
|
|
The randomness source to use for generation. Defaults to ``/dev/urandom``.
|
|
|
|
.. option:: -s
|
|
|
|
Create symlinks ``.key`` and ``.private`` to the generated keys.
|
|
|
|
.. option:: -f
|
|
|
|
Overwrite existing symlinks (for use with ``-s``).
|
|
|
|
.. option:: -h, --help
|
|
|
|
Print the help text (short summary with ``-h``, long help with
|
|
``--help``).
|