Files
NLnetLabs-dnst/doc/manual/source/man/dnst-signzone.rst
T
bfbf492e32 Add manual pages (#26)
* Fix sphinx default language

* Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command.

* Update dnst-nsec3-hash.rst

* Add key2ds manual

* Add dnst-keygen manual

* Change dnst-keygen algorithms to list from table

* Change dnst-keygen algorithms back to table

* Add ldns-keygen manual

* Add notify manuals

* Add signzone manuals

* Add subcommands to dnst manual and table of contents

* Update dnst-nsec3-hash manual

* Add update manual

* Apply feedback

* Apply further feedback

* Move signzone date description into own section

* Update signzone hash iterations manual text

* Add Arguments sections

* Add basic intro text for dnst

* Fix ldns-signzone default nsec3 hash iterations

* Update nse3-hash defaults and wording

* Update dnst-key2ds ignore-sep and force

* Update nse3-hash default to what it is currently in main

---------

Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
2024-11-19 14:26:24 +01:00

119 lines
2.6 KiB
ReStructuredText

dnst signzone
===============
Synopsis
--------
:program:`dnst signzone` ``[OPTIONS]`` ``<ZONEFILE>`` ``<KEY>...``
Description
-----------
**dnst signzone** signs the zonefile with the given key(s).
Keys must be specified by their base name (usually ``K<name>+<alg>+<id>``),
i.e. WITHOUT the ``.private`` or ``.key`` extension. Both ``.private`` and
``.key`` files are required.
Arguments
---------
.. option:: <ZONEFILE>
The zonefile to sign.
.. option:: <KEY>...
The keys to sign the zonefile with.
Options
-------
.. option:: -b
Add comments on DNSSEC records. Without this option only DNSKEY RRs
will have their key tag annotated in the comment.
.. option:: -d
Do not add used keys to the resulting zonefile.
.. option:: -e <DATE>
Set the expiration date of signatures to this date (see
:ref:`dnst-signzone-dates`). Defaults to 4 weeks from now.
.. option:: -f <FILE>
Write signed zone to file. Use ``-f -`` to output to stdout. Defaults to
``<ZONEFILE>.signed``.
.. option:: -i <DATE>
Set the inception date of signatures to this date (see
:ref:`dnst-signzone-dates`). Defaults to now.
.. option:: -o <DOMAIN>
Set the origin for the zone (only necessary for zonefiles with relative
names and no $ORIGIN).
.. option:: -u
Set SOA serial to the number of seconds since Jan 1st 1970.
If this would NOT result in the SOA serial increasing it will be
incremented instead.
.. option:: -n
Use NSEC3 instead of NSEC. By default, RFC 9276 best practice settings
are used: SHA-1, no extra iterations, empty salt. To use different NSEC3
settings see :ref:`dnst-signzone-nsec3-options`.
.. option:: -H
Hash only, don't sign.
.. option:: -h, --help
Print the help text (short summary with ``-h``, long help with
``--help``).
.. _dnst-signzone-nsec3-options:
NSEC3 options
--------------------------------
The following options can be used with ``-n`` to override the default NSEC3
settings used.
.. option:: -a <ALGORITHM NUMBER OR MNEMONIC>
Specify the hashing algorithm. Defaults to SHA-1.
.. option:: -t <NUMBER>
Set the number of extra hash iterations. Defaults to 0.
.. option:: -s <STRING>
Specify the salt as a hex string. Defaults to ``-``, meaning empty salt.
.. option:: -p
Set the opt-out flag on all NSEC3 RRs.
.. option:: -A
Set the opt-out flag on all NSEC3 RRs and skip unsigned delegations.
.. _dnst-signzone-dates:
DATES
-----
A date can be a UNIX timestamp as seconds since the Epoch (1970-01-01
00:00 UTC), or of the form ``<YYYYMMdd[hhmmss]>``.