Files
NLnetLabs-dnst/doc/manual/source/man/dnst-keygen.rst
T
bfbf492e32 Add manual pages (#26)
* Fix sphinx default language

* Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command.

* Update dnst-nsec3-hash.rst

* Add key2ds manual

* Add dnst-keygen manual

* Change dnst-keygen algorithms to list from table

* Change dnst-keygen algorithms back to table

* Add ldns-keygen manual

* Add notify manuals

* Add signzone manuals

* Add subcommands to dnst manual and table of contents

* Update dnst-nsec3-hash manual

* Add update manual

* Apply feedback

* Apply further feedback

* Move signzone date description into own section

* Update signzone hash iterations manual text

* Add Arguments sections

* Add basic intro text for dnst

* Fix ldns-signzone default nsec3 hash iterations

* Update nse3-hash defaults and wording

* Update dnst-key2ds ignore-sep and force

* Update nse3-hash default to what it is currently in main

---------

Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
2024-11-19 14:26:24 +01:00

75 lines
2.1 KiB
ReStructuredText

dnst keygen
===============
Synopsis
--------
:program:`dnst keygen` ``[OPTIONS]`` ``-a <ALGORITHM>`` ``<DOMAIN NAME>``
Description
-----------
**dnst keygen** generates a new key pair for a given domain name.
The following files will be created:
- ``K<name>+<alg>+<tag>.key``: The public key file containing a DNSKEY RR in
zone file format.
- ``K<name>+<alg>+<tag>.private``: The private key file containing the private
key data fields in BIND's *Private-key-format*.
- ``K<name>+<alg>+<tag>.ds``: The public key digest file containing the DS RR
in zone file format. It is only created for key signing keys.
| ``<name>`` is the fully-qualified owner name for the key (with a trailing dot).
| ``<alg>`` is the algorithm number of the key, zero-padded to 3 digits.
| ``<tag>`` is the 16-bit tag of the key, zero-padded to 5 digits.
Upon completion, ``K<name>+<alg>+<tag>`` will be printed.
Options
-------
.. option:: -a <NUMBER OR MNEMONIC>
Use the given signing algorithm.
Possible values are:
=================== ========== =========================
**Mnemonic** **Number** **Description**
=================== ========== =========================
``list`` List available algorithms
``RSASHA256`` 8 RSA with SHA-256
``ECDSAP256SHA256`` 13 ECDSA P-256 with SHA-256
``ECDSAP384SHA384`` 14 ECDSA P-384 with SHA-384
``ED25519`` 15 ED25519
``ED448`` 16 ED448
=================== ========== =========================
.. option:: -k
Generate a key signing key (KSK) instead of a zone signing key (ZSK).
.. option:: -b <BITS>
The length of the key (for RSA keys only). Defaults to 2048.
.. option:: -r <DEVICE>
The randomness source to use for generation. Defaults to ``/dev/urandom``.
.. option:: -s
Create symlinks ``.key`` and ``.private`` to the generated keys.
.. option:: -f
Overwrite existing symlinks (for use with ``-s``).
.. option:: -h, --help
Print the help text (short summary with ``-h``, long help with
``--help``).