Files
NLnetLabs-dnst/doc/manual/source/man/ldns-signzone.rst
T
bfbf492e32 Add manual pages (#26)
* Fix sphinx default language

* Add ldns-nsec3-hash man page based on the original, and adjust the dnst-nsec3-hash page to match the current help output of the command.

* Update dnst-nsec3-hash.rst

* Add key2ds manual

* Add dnst-keygen manual

* Change dnst-keygen algorithms to list from table

* Change dnst-keygen algorithms back to table

* Add ldns-keygen manual

* Add notify manuals

* Add signzone manuals

* Add subcommands to dnst manual and table of contents

* Update dnst-nsec3-hash manual

* Add update manual

* Apply feedback

* Apply further feedback

* Move signzone date description into own section

* Update signzone hash iterations manual text

* Add Arguments sections

* Add basic intro text for dnst

* Fix ldns-signzone default nsec3 hash iterations

* Update nse3-hash defaults and wording

* Update dnst-key2ds ignore-sep and force

* Update nse3-hash default to what it is currently in main

---------

Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
Co-authored-by: Terts Diepraam <terts.diepraam@gmail.com>
2024-11-19 14:26:24 +01:00

110 lines
2.2 KiB
ReStructuredText

ldns-signzone
===============
Synopsis
--------
:program:`ldns-signzone` ``[OPTIONS]`` ``<ZONEFILE>`` ``<KEY>...``
Description
-----------
**ldns-signzone** signs the zone with the given key(s).
Keys must be specified by their base name (usually ``K<name>+<alg>+<id>``),
i.e. WITHOUT the ``.private`` or ``.key`` extension. Both ``.private`` and
``.key`` files are required.
Arguments
---------
.. option:: <ZONEFILE>
The zonefile to sign.
.. option:: <KEY>...
The keys to sign the zonefile with.
Options
-------
.. option:: -b
Add comments on DNSSEC records. Without this option only DNSKEY RRs
will have their key tag annotated in the comment.
.. option:: -d
Do not add used keys to the resulting zonefile.
.. option:: -e <DATE>
Set the expiration date of signatures to this date (see
:ref:`ldns-signzone-dates`). Defaults to 4 weeks from now.
.. option:: -f <FILE>
Write signed zone to file. Use ``-f -`` to output to stdout. Defaults to
``<ZONEFILE>.signed``.
.. option:: -i <DATE>
Set the inception date of signatures to this date (see
:ref:`ldns-signzone-dates`). Defaults to now.
.. option:: -o <DOMAIN>
Set the origin for the zone (only necessary for zonefiles with
relative names and no $ORIGIN).
.. option:: -u
Set SOA serial to the number of seconds since Jan 1st 1970.
.. option:: -n
Use NSEC3 instead of NSEC. If specified, you can use extra options (see
:ref:`ldns-signzone-nsec3-options`).
.. option:: -h
Print the help text.
.. option:: -v
Print the version and exit.
.. _ldns-signzone-nsec3-options:
NSEC3 options
--------------------------------
The following options can be used with ``-n`` to override the default NSEC3
settings used.
.. option:: -a <ALGORITHM>
Specify the hashing algorithm. Defaults to SHA-1.
.. option:: -t <NUMBER>
Set the number of extra hash iterations. Defaults to 1.
.. option:: -s <STRING>
Specify the salt as a hex string. Defaults to ``-``, meaning empty salt.
.. option:: -p
Set the opt-out flag on all NSEC3 RRs.
.. _ldns-signzone-dates:
DATES
-----
A date can be a UNIX timestamp as seconds since the Epoch (1970-01-01
00:00 UTC), or of the form ``<YYYYMMdd[hhmmss]>``.