to the standard output. This is an identification string for
the key it has generated. These strings can be used as arguments
to \fBdnssec-makekeyset\fR.
-.PP
+.TP 0.2i
+\(bu
\fInnnn\fR is the key name.
-.PP
-\fIaaa\fR is the numeric representation of the algorithm.
-.PP
+.TP 0.2i
+\(bu
+\fIaaa\fR is the numeric representation of the
+algorithm.
+.TP 0.2i
+\(bu
\fIiiiii\fR is the key identifier (or footprint).
.PP
\fBdnssec-keygen\fR creates two file, with names based
\fIKnnnn.+aaa+iiiii.private\fR contains the private
key.
.PP
+.PP
The \fI.key\fR file contains a DNS KEY record that
can be inserted into a zone file (directly or with a $INCLUDE
statement).
.PP
+.PP
The \fI.private\fR file contains algorithm specific
fields. For obvious security reasons, this file does not have
general read permission.
.PP
+.PP
Both \fI.key\fR and \fI.private\fR
files are generated for symmetric encryption algorithm such as
HMAC-MD5, even though the public and private key are equivalent.
+.PP
.SH "EXAMPLE"
.PP
To generate a 768-bit DSA key for the domain
the key it has generated. These strings can be used as arguments
to <command>dnssec-makekeyset</command>.
</para>
- <para>
- <filename>nnnn</filename> is the key name.
- </para>
- <para>
- <filename>aaa</filename> is the numeric representation of the algorithm.
- </para>
- <para>
- <filename>iiiii</filename> is the key identifier (or footprint).
- </para>
+ <itemizedlist>
+ <listitem>
+ <para>
+ <filename>nnnn</filename> is the key name.
+ </para>
+ </listitem>
+ <listitem>
+ <para>
+ <filename>aaa</filename> is the numeric representation of the
+ algorithm.
+ </para>
+ </listitem>
+ <listitem>
+ <para>
+ <filename>iiiii</filename> is the key identifier (or footprint).
+ </para>
+ </listitem>
+ </itemizedlist>
<para>
<command>dnssec-keygen</command> creates two file, with names based
on the printed string. <filename>Knnnn.+aaa+iiiii.key</filename>
>.
</P
><P
-> <TT
+></P
+><UL
+><LI
+><P
+> <TT
CLASS="FILENAME"
>nnnn</TT
> is the key name.
- </P
+ </P
+></LI
+><LI
><P
-> <TT
+> <TT
CLASS="FILENAME"
>aaa</TT
-> is the numeric representation of the algorithm.
- </P
+> is the numeric representation of the
+ algorithm.
+ </P
+></LI
+><LI
><P
-> <TT
+> <TT
CLASS="FILENAME"
>iiiii</TT
> is the key identifier (or footprint).
- </P
+ </P
+></LI
+></UL
><P
> <B
CLASS="COMMAND"
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN144"
+NAME="AEN148"
></A
><H2
>EXAMPLE</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN157"
+NAME="AEN161"
></A
><H2
>SEE ALSO</H2
><DIV
CLASS="REFSECT1"
><A
-NAME="AEN173"
+NAME="AEN177"
></A
><H2
>AUTHOR</H2