mirror of
https://github.com/NLnetLabs/dnst.git
synced 2026-09-28 04:34:57 +02:00
* Fix sphinx default language * Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command. * Update dnst-nsec3-hash.rst * Add key2ds manual * Add dnst-keygen manual * Change dnst-keygen algorithms to list from table * Change dnst-keygen algorithms back to table * Add ldns-keygen manual * Add notify manuals * Add signzone manuals * Add subcommands to dnst manual and table of contents * Update dnst-nsec3-hash manual * Add update manual * Apply feedback * Apply further feedback * Move signzone date description into own section * Update signzone hash iterations manual text * Add Arguments sections * Add basic intro text for dnst * Fix ldns-signzone default nsec3 hash iterations * Update nse3-hash defaults and wording * Update dnst-key2ds ignore-sep and force * Update nse3-hash default to what it is currently in main --------- Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com> Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
61 lines
1.7 KiB
ReStructuredText
61 lines
1.7 KiB
ReStructuredText
ldns-keygen
|
|
===============
|
|
|
|
Synopsis
|
|
--------
|
|
|
|
:program:`ldns-keygen` ``[OPTIONS]`` ``<DOMAIN NAME>``
|
|
|
|
Description
|
|
-----------
|
|
|
|
**ldns-keygen** is used to generate a private/public keypair. When run, it will
|
|
create 3 files; a ``.key`` file with the public DNSKEY, a ``.private`` file
|
|
with the private keydata and a ``.ds`` file with the DS record of the DNSKEY
|
|
record.
|
|
|
|
.. **ldns-keygen** can also be used to create symmetric keys (for TSIG) by
|
|
.. selecting the appropriate algorithm: hmac-md5.sig-alg.reg.int, hmac-sha1,
|
|
.. hmac-sha224, hmac-sha256, hmac-sha384 or hmac-sha512. In that case no DS record
|
|
.. will be created and no .ds file.
|
|
|
|
ldns-keygen prints the basename for the key files: ``K<name>+<alg>+<id>``
|
|
|
|
Options
|
|
-------
|
|
|
|
.. option:: -a <ALGORITHM>
|
|
|
|
Create a key with this algorithm. Specifying 'list' here gives a list of
|
|
supported algorithms. Several alias names are also accepted (from older
|
|
versions and other software), the list gives names from the RFC. Also the
|
|
plain algorithm number is accepted.
|
|
|
|
.. option:: -b <BITS>
|
|
|
|
Use this many bits for the key length.
|
|
|
|
.. option:: -k
|
|
|
|
When given, generate a key signing key. This just sets the flag field to
|
|
257 instead of 256 in the DNSKEY RR in the .key file.
|
|
|
|
.. option:: -r <DEVICE>
|
|
|
|
Make ldns-keygen use this file to seed the random generator with. This
|
|
will default to /dev/random.
|
|
|
|
.. option:: -s
|
|
|
|
ldns-keygen will create symbolic links named ``.private`` to the new
|
|
generated private key, ``.key`` to the public DNSKEY and ``.ds`` to the
|
|
file containing DS record data.
|
|
|
|
.. option:: -f
|
|
|
|
Force symlinks to be overwritten if they exist.
|
|
|
|
.. option:: -v
|
|
|
|
Show the version and exit
|