From: Mark Andrews
+trusted-key=####
- Specify a trusted key to be used with
- +sigchase.
+
+ Specifies a file containing trusted keys to be used with
+ +sigchase. Each DNSKEY record must be
+ on its own line.
+
+ If not specified dig will look for
+ /etc/trusted-key.key then
+ trusted-key.key in the current directory.
+
Requires dig be compiled with -DDIG_SIGCHASE. -
+[no]topdownWhen chasing DNSSEC signature chains perform a top down @@ -527,7 +537,7 @@
The BIND 9 implementation of dig supports @@ -573,14 +583,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
host(1), named(8), dnssec-keygen(8), @@ -588,7 +598,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
There are probably too many query options.
diff --git a/bin/dnssec/dnssec-keygen.8 b/bin/dnssec/dnssec-keygen.8 index 7d1aee67523..6529ff8f2ac 100644 --- a/bin/dnssec/dnssec-keygen.8 +++ b/bin/dnssec/dnssec-keygen.8 @@ -13,7 +13,7 @@ .\" OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR .\" PERFORMANCE OF THIS SOFTWARE. .\" -.\" $Id: dnssec-keygen.8,v 1.31 2005/05/13 03:14:04 marka Exp $ +.\" $Id: dnssec-keygen.8,v 1.32 2005/08/30 04:18:55 marka Exp $ .\" .hy 0 .ad l @@ -92,7 +92,7 @@ Indicates the use of the key\&. \fBtype\fR must be one of AUTHCONF, NOAUTHCONF, Sets the debugging level\&. .SH "GENERATED KEYS" .PP -When \fBdnssec\-keygen\fR completes successfully, it prints a string of the form \fIKnnnn\&.+aaa+iiiii\fR to the standard output\&. This is an identification string for the key it has generated\&. These strings can be used as arguments to \fBdnssec\-makekeyset\fR\&. +When \fBdnssec\-keygen\fR completes successfully, it prints a string of the form \fIKnnnn\&.+aaa+iiiii\fR to the standard output\&. This is an identification string for the key it has generated\&. .TP 3 \(bu \fInnnn\fR is the key name\&. diff --git a/bin/dnssec/dnssec-keygen.html b/bin/dnssec/dnssec-keygen.html index 0b6b822728b..9e740dac004 100644 --- a/bin/dnssec/dnssec-keygen.html +++ b/bin/dnssec/dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -154,8 +154,7 @@ successfully, it prints a string of the formKnnnn.+aaa+iiiii
to the standard output. This is an identification string for
- the key it has generated. These strings can be used as arguments
- to dnssec-makekeyset.
+ the key it has generated.
nnnn is the key name.
@@ -195,7 +194,7 @@
To generate a 768-bit DSA key for the domain
example.com, the following command would be
@@ -216,7 +215,7 @@
dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -225,7 +224,7 @@
dig [global-queryopt...] [query...]
dig (domain information groper) is a flexible tool for interrogating DNS name servers. It performs DNS lookups and @@ -91,7 +91,7 @@
The -b option sets the source IP address of the query
to address. This must be a valid
@@ -236,7 +236,7 @@
dig provides a number of query options which affect the way in which lookups are made and the results displayed. Some of @@ -528,11 +528,21 @@ -DDIG_SIGCHASE.
+trusted-key=####
- Specify a trusted key to be used with
- +sigchase.
+
+ Specifies a file containing trusted keys to be used with
+ +sigchase. Each DNSKEY record must be
+ on its own line.
+
+ If not specified dig will look for
+ /etc/trusted-key.key then
+ trusted-key.key in the current directory.
+
Requires dig be compiled with -DDIG_SIGCHASE. -
+[no]topdownWhen chasing DNSSEC signature chains perform a top down @@ -545,7 +555,7 @@
The BIND 9 implementation of dig supports @@ -591,14 +601,14 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
host(1), named(8), dnssec-keygen(8), @@ -606,7 +616,7 @@ dig +qr www.isc.org any -x 127.0.0.1 isc.org ns +noqr
There are probably too many query options.
diff --git a/doc/arm/man.dnssec-keygen.html b/doc/arm/man.dnssec-keygen.html index 6a01c4f6b84..ce1cdac91d8 100644 --- a/doc/arm/man.dnssec-keygen.html +++ b/doc/arm/man.dnssec-keygen.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,7 +50,7 @@dnssec-keygen {-a algorithm} {-b keysize} {-n nametype} [-c ] [class-e] [-f ] [flag-g ] [generator-h] [-k] [-p ] [protocol-r ] [randomdev-s ] [strength-t ] [type-v ] {name}level
dnssec-keygen generates keys for DNSSEC (Secure DNS), as defined in RFC 2535 and RFC <TBA\>. It can also generate keys for use with @@ -58,7 +58,7 @@
When dnssec-keygen completes
successfully,
it prints a string of the form Knnnn.+aaa+iiiii
to the standard output. This is an identification string for
- the key it has generated. These strings can be used as arguments
- to dnssec-makekeyset.
+ the key it has generated.
nnnn is the key name.
@@ -213,7 +212,7 @@
To generate a 768-bit DSA key for the domain
example.com, the following command would be
@@ -234,7 +233,7 @@
dnssec-signzone(8), BIND 9 Administrator Reference Manual, RFC 2535, @@ -243,7 +242,7 @@
dnssec-signzone [-a] [-c ] [class-d ] [directory-e ] [end-time-f ] [output-file-g] [-h] [-k ] [key-l ] [domain-i ] [interval-I ] [input-format-j ] [jitter-n ] [nthreads-o ] [origin-O ] [output-format-p] [-r ] [randomdev-s ] [start-time-t] [-v ] [level-z] {zonefile} [key...]
dnssec-signzone signs a zone. It generates NSEC and RRSIG records and produces a signed version of the @@ -61,7 +61,7 @@
The following command signs the example.com
zone with the DSA key generated in the dnssec-keygen
@@ -264,14 +264,14 @@
host [-aCdlnrsTwv] [-c ] [class-N ] [ndots-R ] [number-t ] [type-W ] [wait-m ] [flag-4] [-6] {name} [server]
host is a simple utility for performing DNS lookups. It is normally used to convert names to IP addresses and vice versa. @@ -202,12 +202,12 @@
dig(1), named(8).
diff --git a/doc/arm/man.named-checkconf.html b/doc/arm/man.named-checkconf.html index 24e0171d474..42ae2af0dc0 100644 --- a/doc/arm/man.named-checkconf.html +++ b/doc/arm/man.named-checkconf.html @@ -14,7 +14,7 @@ - OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR - PERFORMANCE OF THIS SOFTWARE. --> - + @@ -50,14 +50,14 @@named-checkconf [-v] [-j] [-t ] {filename} [directory-z]
named-checkconf checks the syntax, but not the semantics, of a named configuration file.
named-checkconf returns an exit status of 1 if errors were detected and 0 otherwise.
named-compilezone [-d] [-j] [-q] [-v] [-c ] [class-f ] [format-F ] [format-i ] [mode-k ] [mode-m ] [mode-n ] [mode-o ] [filename-s ] [style-t ] [directory-w ] [directory-D] [-W ] {zonename} {filename}mode
named-checkzone checks the syntax and integrity of a zone file. It performs the same checks as named does when loading a @@ -71,7 +71,7 @@
named-checkzone returns an exit status of 1 if errors were detected and 0 otherwise.
named [-4] [-6] [-c ] [config-file-d ] [debug-level-f] [-g] [-n ] [#cpus-p ] [port-s] [-t ] [directory-u ] [user-v] [-x ]cache-file
named is a Domain Name System (DNS) server, part of the BIND 9 distribution from ISC. For more @@ -65,7 +65,7 @@
In routine operation, signals should not be used to control the nameserver; rndc should be used @@ -219,7 +219,7 @@
The named configuration file is too complex to describe in detail here. A complete description is provided @@ -228,7 +228,7 @@
rndc-confgen [-a] [-b ] [keysize-c ] [keyfile-h] [-k ] [keyname-p ] [port-r ] [randomfile-s ] [address-t ] [chrootdir-u ]user
rndc-confgen generates configuration files for rndc. It can be used as a @@ -64,7 +64,7 @@
rndc.conf
rndc.conf is the configuration file
for rndc, the BIND 9 name server control
utility. This file has a similar structure and syntax to
@@ -135,7 +135,7 @@
The name server must be configured to accept rndc connections and
to recognize the key specified in the rndc.conf
@@ -219,7 +219,7 @@
rndc [-b ] [source-address-c ] [config-file-k ] [key-file-s ] [server-p ] [port-V] [-y ] {command}key_id