Files
NLnetLabs-dnst/doc/manual/source/man/ldns-keygen.rst
T
bfbf492e32 Add manual pages (#26)
* Fix sphinx default language

* Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command.

* Update dnst-nsec3-hash.rst

* Add key2ds manual

* Add dnst-keygen manual

* Change dnst-keygen algorithms to list from table

* Change dnst-keygen algorithms back to table

* Add ldns-keygen manual

* Add notify manuals

* Add signzone manuals

* Add subcommands to dnst manual and table of contents

* Update dnst-nsec3-hash manual

* Add update manual

* Apply feedback

* Apply further feedback

* Move signzone date description into own section

* Update signzone hash iterations manual text

* Add Arguments sections

* Add basic intro text for dnst

* Fix ldns-signzone default nsec3 hash iterations

* Update nse3-hash defaults and wording

* Update dnst-key2ds ignore-sep and force

* Update nse3-hash default to what it is currently in main

---------

Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
2024-11-19 14:26:24 +01:00

61 lines
1.7 KiB
ReStructuredText

ldns-keygen
===============
Synopsis
--------
:program:`ldns-keygen` ``[OPTIONS]`` ``<DOMAIN NAME>``
Description
-----------
**ldns-keygen** is used to generate a private/public keypair. When run, it will
create 3 files; a ``.key`` file with the public DNSKEY, a ``.private`` file
with the private keydata and a ``.ds`` file with the DS record of the DNSKEY
record.
.. **ldns-keygen** can also be used to create symmetric keys (for TSIG) by
.. selecting the appropriate algorithm: hmac-md5.sig-alg.reg.int, hmac-sha1,
.. hmac-sha224, hmac-sha256, hmac-sha384 or hmac-sha512. In that case no DS record
.. will be created and no .ds file.
ldns-keygen prints the basename for the key files: ``K<name>+<alg>+<id>``
Options
-------
.. option:: -a <ALGORITHM>
Create a key with this algorithm. Specifying 'list' here gives a list of
supported algorithms. Several alias names are also accepted (from older
versions and other software), the list gives names from the RFC. Also the
plain algorithm number is accepted.
.. option:: -b <BITS>
Use this many bits for the key length.
.. option:: -k
When given, generate a key signing key. This just sets the flag field to
257 instead of 256 in the DNSKEY RR in the .key file.
.. option:: -r <DEVICE>
Make ldns-keygen use this file to seed the random generator with. This
will default to /dev/random.
.. option:: -s
ldns-keygen will create symbolic links named ``.private`` to the new
generated private key, ``.key`` to the public DNSKEY and ``.ds`` to the
file containing DS record data.
.. option:: -f
Force symlinks to be overwritten if they exist.
.. option:: -v
Show the version and exit