mirror of
https://github.com/NLnetLabs/dnst.git
synced 2026-09-28 04:34:57 +02:00
* Fix sphinx default language * Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command. * Update dnst-nsec3-hash.rst * Add key2ds manual * Add dnst-keygen manual * Change dnst-keygen algorithms to list from table * Change dnst-keygen algorithms back to table * Add ldns-keygen manual * Add notify manuals * Add signzone manuals * Add subcommands to dnst manual and table of contents * Update dnst-nsec3-hash manual * Add update manual * Apply feedback * Apply further feedback * Move signzone date description into own section * Update signzone hash iterations manual text * Add Arguments sections * Add basic intro text for dnst * Fix ldns-signzone default nsec3 hash iterations * Update nse3-hash defaults and wording * Update dnst-key2ds ignore-sep and force * Update nse3-hash default to what it is currently in main --------- Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
119 lines
2.6 KiB
ReStructuredText
119 lines
2.6 KiB
ReStructuredText
dnst signzone
|
|
===============
|
|
|
|
Synopsis
|
|
--------
|
|
|
|
:program:`dnst signzone` ``[OPTIONS]`` ``<ZONEFILE>`` ``<KEY>...``
|
|
|
|
Description
|
|
-----------
|
|
|
|
**dnst signzone** signs the zonefile with the given key(s).
|
|
|
|
Keys must be specified by their base name (usually ``K<name>+<alg>+<id>``),
|
|
i.e. WITHOUT the ``.private`` or ``.key`` extension. Both ``.private`` and
|
|
``.key`` files are required.
|
|
|
|
Arguments
|
|
---------
|
|
|
|
.. option:: <ZONEFILE>
|
|
|
|
The zonefile to sign.
|
|
|
|
.. option:: <KEY>...
|
|
|
|
The keys to sign the zonefile with.
|
|
|
|
Options
|
|
-------
|
|
|
|
.. option:: -b
|
|
|
|
Add comments on DNSSEC records. Without this option only DNSKEY RRs
|
|
will have their key tag annotated in the comment.
|
|
|
|
.. option:: -d
|
|
|
|
Do not add used keys to the resulting zonefile.
|
|
|
|
.. option:: -e <DATE>
|
|
|
|
Set the expiration date of signatures to this date (see
|
|
:ref:`dnst-signzone-dates`). Defaults to 4 weeks from now.
|
|
|
|
.. option:: -f <FILE>
|
|
|
|
Write signed zone to file. Use ``-f -`` to output to stdout. Defaults to
|
|
``<ZONEFILE>.signed``.
|
|
|
|
.. option:: -i <DATE>
|
|
|
|
Set the inception date of signatures to this date (see
|
|
:ref:`dnst-signzone-dates`). Defaults to now.
|
|
|
|
.. option:: -o <DOMAIN>
|
|
|
|
Set the origin for the zone (only necessary for zonefiles with relative
|
|
names and no $ORIGIN).
|
|
|
|
.. option:: -u
|
|
|
|
Set SOA serial to the number of seconds since Jan 1st 1970.
|
|
|
|
If this would NOT result in the SOA serial increasing it will be
|
|
incremented instead.
|
|
|
|
.. option:: -n
|
|
|
|
Use NSEC3 instead of NSEC. By default, RFC 9276 best practice settings
|
|
are used: SHA-1, no extra iterations, empty salt. To use different NSEC3
|
|
settings see :ref:`dnst-signzone-nsec3-options`.
|
|
|
|
.. option:: -H
|
|
|
|
Hash only, don't sign.
|
|
|
|
.. option:: -h, --help
|
|
|
|
Print the help text (short summary with ``-h``, long help with
|
|
``--help``).
|
|
|
|
|
|
.. _dnst-signzone-nsec3-options:
|
|
|
|
NSEC3 options
|
|
--------------------------------
|
|
|
|
The following options can be used with ``-n`` to override the default NSEC3
|
|
settings used.
|
|
|
|
.. option:: -a <ALGORITHM NUMBER OR MNEMONIC>
|
|
|
|
Specify the hashing algorithm. Defaults to SHA-1.
|
|
|
|
.. option:: -t <NUMBER>
|
|
|
|
Set the number of extra hash iterations. Defaults to 0.
|
|
|
|
.. option:: -s <STRING>
|
|
|
|
Specify the salt as a hex string. Defaults to ``-``, meaning empty salt.
|
|
|
|
.. option:: -p
|
|
|
|
Set the opt-out flag on all NSEC3 RRs.
|
|
|
|
.. option:: -A
|
|
|
|
Set the opt-out flag on all NSEC3 RRs and skip unsigned delegations.
|
|
|
|
.. _dnst-signzone-dates:
|
|
|
|
DATES
|
|
-----
|
|
|
|
A date can be a UNIX timestamp as seconds since the Epoch (1970-01-01
|
|
00:00 UTC), or of the form ``<YYYYMMdd[hhmmss]>``.
|