head 1.1; access; symbols perseant-exfatfs-base-20240630:1.1 perseant-exfatfs:1.1.0.28 perseant-exfatfs-base:1.1 cjep_sun2x:1.1.0.26 cjep_sun2x-base:1.1 cjep_staticlib_x-base1:1.1 cjep_staticlib_x:1.1.0.24 cjep_staticlib_x-base:1.1 phil-wifi-20200421:1.1 phil-wifi-20200411:1.1 phil-wifi-20200406:1.1 pgoyette-compat-merge-20190127:1.1 pgoyette-compat-20190127:1.1 pgoyette-compat-20190118:1.1 pgoyette-compat-1226:1.1 pgoyette-compat-1126:1.1 pgoyette-compat-1020:1.1 pgoyette-compat-0930:1.1 pgoyette-compat-0906:1.1 pgoyette-compat-0728:1.1 pgoyette-compat-0625:1.1 pgoyette-compat-0521:1.1 pgoyette-compat-0502:1.1 pgoyette-compat-0422:1.1 pgoyette-compat-0415:1.1 pgoyette-compat-0407:1.1 pgoyette-compat-0330:1.1 pgoyette-compat-0322:1.1 pgoyette-compat-0315:1.1 pgoyette-compat:1.1.0.22 pgoyette-compat-base:1.1 prg-localcount2-base3:1.1 prg-localcount2-base2:1.1 prg-localcount2-base1:1.1 prg-localcount2:1.1.0.20 prg-localcount2-base:1.1 pgoyette-localcount-20170426:1.1 bouyer-socketcan-base1:1.1 pgoyette-localcount-20170320:1.1 bouyer-socketcan:1.1.0.18 bouyer-socketcan-base:1.1 pgoyette-localcount-20170107:1.1 pgoyette-localcount-20161104:1.1 localcount-20160914:1.1 pgoyette-localcount-20160806:1.1 pgoyette-localcount-20160726:1.1 pgoyette-localcount:1.1.0.16 pgoyette-localcount-base:1.1 netbsd-5-2-3-RELEASE:1.1.2.1 netbsd-5-1-5-RELEASE:1.1.4.2 yamt-pagecache-base9:1.1 yamt-pagecache-tag8:1.1 tls-earlyentropy:1.1.0.12 tls-earlyentropy-base:1.1 riastradh-xf86-video-intel-2-7-1-pre-2-21-15:1.1 riastradh-drm2-base3:1.1 netbsd-5-2-2-RELEASE:1.1.2.1 netbsd-5-1-4-RELEASE:1.1.4.2 netbsd-5-2-1-RELEASE:1.1.2.1 netbsd-5-1-3-RELEASE:1.1.4.2 agc-symver:1.1.0.14 agc-symver-base:1.1 tls-maxphys-base:1.1 yamt-pagecache-base8:1.1 netbsd-5-2:1.1.2.1.0.2 yamt-pagecache-base7:1.1 netbsd-5-2-RELEASE:1.1.2.1 netbsd-5-2-RC1:1.1.2.1 yamt-pagecache-base6:1.1 yamt-pagecache-base5:1.1 yamt-pagecache-base4:1.1 netbsd-5-1-2-RELEASE:1.1.4.2 netbsd-5-1-1-RELEASE:1.1.4.2 yamt-pagecache-base3:1.1 yamt-pagecache-base2:1.1 yamt-pagecache:1.1.0.10 yamt-pagecache-base:1.1 bind-9-7-3-P1:1.1.1.1 ISC:1.1.1 bouyer-quota2-nbase:1.1 bouyer-quota2:1.1.0.8 bouyer-quota2-base:1.1 netbsd-5-0:1.1.0.6 netbsd-5-1:1.1.0.4 netbsd-5:1.1.0.2; locks; strict; comment @# @; 1.1 date 2011.01.06.21.41.13; author riz; state dead; branches 1.1.1.1 1.1.2.1 1.1.4.1 1.1.6.1; next ; 1.1.1.1 date 2011.06.03.19.48.55; author spz; state Exp; branches; next ; 1.1.2.1 date 2011.01.06.21.41.13; author riz; state Exp; branches; next ; 1.1.4.1 date 2011.01.06.21.41.13; author riz; state dead; branches; next 1.1.4.2; 1.1.4.2 date 2011.01.09.20.41.49; author riz; state Exp; branches; next ; 1.1.6.1 date 2011.01.06.21.41.13; author riz; state dead; branches; next 1.1.6.2; 1.1.6.2 date 2011.01.10.00.38.33; author riz; state Exp; branches; next ; desc @@ 1.1 log @file zkt-ls.8.html was initially added on branch netbsd-5. @ text @@ 1.1.1.1 log @Import bind 9.7.3-P1 @ text @a0 382 zkt-ls

zkt-ls

NAME
SYNOPSYS
DESCRIPTION
GENERAL OPTIONS
COMMAND OPTIONS
SAMPLE USAGE
ENVIRONMENT VARIABLES
FILES
BUGS
AUTHORS
COPYRIGHT
SEE ALSO

NAME

zkt−ls — list dnskeys

SYNOPSYS

zkt−ls −H

zkt−ls [−V|--view view] [−c file] [−l list] [−adefhkLprtz] [{keyfile|dir} ...]

zkt−ls −T [−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]
zkt−ls −−list-trustedkeys
[−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]

zkt−ls −K [−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]
zkt−ls −−list-dnskeys
[−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]

DESCRIPTION

The zkt-ls command list all dnssec zone keys found in the given or predefined default directory. It is also possible to specify keyfiles (K*.key) as arguments. With option −r subdirectories will be searched recursively and all dnssec keys found are listed, sorted by domain name, key type and generation time. In that mode the use of option −p may be helpful to find the location of the keyfile in the directory tree.

Other forms of the command, print out keys in a format suitable for a trusted-key section (−T) or as a DNSKEY (−K) resource record.

GENERAL OPTIONS

−V view, −−view=view

Try to read the default configuration out of a file named dnssec-<view>.conf . Instead of specifying the −V or --view option every time, it is also possible to create a hard or softlink to the executable file to give it an additional name like zkt-ls-<view> .

−c file, −−config=file

Read default values from the specified config file. Otherwise the default config file is read or build in defaults will be used.

−O optstr, −−config-option=optstr

Set any config file option via the commandline. Several config file options could be specified at the argument string but have to be delimited by semicolon (or newline).

−l list, −−label=list

Print out information solely about domains given in the comma or space separated list. Take care of, that every domain name has a trailing dot.

−d, −−directory

Skip directory arguments. This will be useful in combination with wildcard arguments to prevent dnsssec-zkt to list all keys found in subdirectories. For example "zkt-ls -d *" will print out a list of all keys only found in the current directory. Maybe it is easier to use "zkt-ls ." instead (without -r set). The option works similar to the −d option of ls(1).

−L, −−left-justify

Print out the domain name left justified.

−k, −−ksk

Select and print key signing keys only (default depends on command mode).

−z, −−zsk

Select and print zone signing keys only (default depends on command mode).

−r, −−recursive

Recursive mode (default is off).
Also settable in the dnssec.conf file (Parameter: Recursive).

−p, −−path

Print pathname in listing mode. In -C mode, don’t create the new key in the same directory as (already existing) keys with the same label.

−a, −−age

Print age of key in weeks, days, hours, minutes and seconds (default is off).
Also settable in the dnssec.conf file (Parameter: PrintAge).

−f, −−lifetime

Print the key lifetime.

−e, −−exptime

Print the key expiration time.

−t, −−time

Print the key generation time (default is on).
Also settable in the dnssec.conf file (Parameter: PrintTime).

−h

No header or trusted-key section header and trailer in -T mode

COMMAND OPTIONS

−H, −−help

Print out the online help.

−T, −−list-trustedkeys

List all key signing keys as a named.conf trusted-key section. Use −h to supress the section header/trailer.

−K, −−list-dnskeys

List the public part of all the keys in DNSKEY resource record format. Use −h to suppress comment lines.

SAMPLE USAGE

zkt−ls −r .

Print out a list of all zone keys found below the current directory.

zkt−ls −Z −c ""

Print out the compiled in default parameters.

zkt−ls −T ./zonedir/example.net

Print out a trusted-key section containing the key signing keys of "example.net".

zkt−ls --view intern

Print out a list of all zone keys found below the directory where all the zones of view intern live. There should be a seperate dnssec config file dnssec-intern.conf with a directory option to take affect of this.

zkt−ls−intern

Same as above. The binary file zkt−ls has another link, named zkt−ls−intern made, and zkt−ls examines argv[0] to find a view whose zones it proceeds to process.

ENVIRONMENT VARIABLES

ZKT_CONFFILE

Specifies the name of the default global configuration files.

FILES

/var/named/dnssec.conf

Built-in default global configuration file. The name of the default global config file is settable via the environment variable ZKT_CONFFILE.

/var/named/dnssec-<view>.conf

View specific global configuration file.

./dnssec.conf

Local configuration file (only used in −C mode).

BUGS

Some of the general options will not be meaningful in all of the command modes.
The option −l and the ksk rollover options insist on domain names ending with a dot.

AUTHORS

Holger Zuleger

COPYRIGHT

Copyright (c) 2005 − 2010 by Holger Zuleger. Licensed under the BSD Licences. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), rndc(8), named.conf(5), zkt-conf(8), zkt-keyman(8), zkt-signer(8)
RFC4641 "DNSSEC Operational Practices" by Miek Gieben and Olaf Kolkman,
DNSSEC HOWTO Tutorial by Olaf Kolkman, RIPE NCC
(http://www.nlnetlabs.nl/dnssec_howto/)


@ 1.1.6.1 log @file zkt-ls.8.html was added on branch netbsd-5-0 on 2011-01-10 00:38:33 +0000 @ text @@ 1.1.6.2 log @Apply patches (requested by spz in ticket #1517): Update bind to 9.7.2-P3. @ text @a0 382 zkt-ls

zkt-ls

NAME
SYNOPSYS
DESCRIPTION
GENERAL OPTIONS
COMMAND OPTIONS
SAMPLE USAGE
ENVIRONMENT VARIABLES
FILES
BUGS
AUTHORS
COPYRIGHT
SEE ALSO

NAME

zkt−ls — list dnskeys

SYNOPSYS

zkt−ls −H

zkt−ls [−V|--view view] [−c file] [−l list] [−adefhkLprtz] [{keyfile|dir} ...]

zkt−ls −T [−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]
zkt−ls −−list-trustedkeys
[−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]

zkt−ls −K [−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]
zkt−ls −−list-dnskeys
[−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]

DESCRIPTION

The zkt-ls command list all dnssec zone keys found in the given or predefined default directory. It is also possible to specify keyfiles (K*.key) as arguments. With option −r subdirectories will be searched recursively and all dnssec keys found are listed, sorted by domain name, key type and generation time. In that mode the use of option −p may be helpful to find the location of the keyfile in the directory tree.

Other forms of the command, print out keys in a format suitable for a trusted-key section (−T) or as a DNSKEY (−K) resource record.

GENERAL OPTIONS

−V view, −−view=view

Try to read the default configuration out of a file named dnssec-<view>.conf . Instead of specifying the −V or --view option every time, it is also possible to create a hard or softlink to the executable file to give it an additional name like zkt-ls-<view> .

−c file, −−config=file

Read default values from the specified config file. Otherwise the default config file is read or build in defaults will be used.

−O optstr, −−config-option=optstr

Set any config file option via the commandline. Several config file options could be specified at the argument string but have to be delimited by semicolon (or newline).

−l list, −−label=list

Print out information solely about domains given in the comma or space separated list. Take care of, that every domain name has a trailing dot.

−d, −−directory

Skip directory arguments. This will be useful in combination with wildcard arguments to prevent dnsssec-zkt to list all keys found in subdirectories. For example "zkt-ls -d *" will print out a list of all keys only found in the current directory. Maybe it is easier to use "zkt-ls ." instead (without -r set). The option works similar to the −d option of ls(1).

−L, −−left-justify

Print out the domain name left justified.

−k, −−ksk

Select and print key signing keys only (default depends on command mode).

−z, −−zsk

Select and print zone signing keys only (default depends on command mode).

−r, −−recursive

Recursive mode (default is off).
Also settable in the dnssec.conf file (Parameter: Recursive).

−p, −−path

Print pathname in listing mode. In -C mode, don’t create the new key in the same directory as (already existing) keys with the same label.

−a, −−age

Print age of key in weeks, days, hours, minutes and seconds (default is off).
Also settable in the dnssec.conf file (Parameter: PrintAge).

−f, −−lifetime

Print the key lifetime.

−e, −−exptime

Print the key expiration time.

−t, −−time

Print the key generation time (default is on).
Also settable in the dnssec.conf file (Parameter: PrintTime).

−h

No header or trusted-key section header and trailer in -T mode

COMMAND OPTIONS

−H, −−help

Print out the online help.

−T, −−list-trustedkeys

List all key signing keys as a named.conf trusted-key section. Use −h to supress the section header/trailer.

−K, −−list-dnskeys

List the public part of all the keys in DNSKEY resource record format. Use −h to suppress comment lines.

SAMPLE USAGE

zkt−ls −r .

Print out a list of all zone keys found below the current directory.

zkt−ls −Z −c ""

Print out the compiled in default parameters.

zkt−ls −T ./zonedir/example.net

Print out a trusted-key section containing the key signing keys of "example.net".

zkt−ls --view intern

Print out a list of all zone keys found below the directory where all the zones of view intern live. There should be a seperate dnssec config file dnssec-intern.conf with a directory option to take affect of this.

zkt−ls−intern

Same as above. The binary file zkt−ls has another link, named zkt−ls−intern made, and zkt−ls examines argv[0] to find a view whose zones it proceeds to process.

ENVIRONMENT VARIABLES

ZKT_CONFFILE

Specifies the name of the default global configuration files.

FILES

/var/named/dnssec.conf

Built-in default global configuration file. The name of the default global config file is settable via the environment variable ZKT_CONFFILE.

/var/named/dnssec-<view>.conf

View specific global configuration file.

./dnssec.conf

Local configuration file (only used in −C mode).

BUGS

Some of the general options will not be meaningful in all of the command modes.
The option −l and the ksk rollover options insist on domain names ending with a dot.

AUTHORS

Holger Zuleger

COPYRIGHT

Copyright (c) 2005 − 2010 by Holger Zuleger. Licensed under the BSD Licences. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), rndc(8), named.conf(5), zkt-conf(8), zkt-keyman(8), zkt-signer(8)
RFC4641 "DNSSEC Operational Practices" by Miek Gieben and Olaf Kolkman,
DNSSEC HOWTO Tutorial by Olaf Kolkman, RIPE NCC
(http://www.nlnetlabs.nl/dnssec_howto/)


@ 1.1.4.1 log @file zkt-ls.8.html was added on branch netbsd-5-1 on 2011-01-09 20:41:49 +0000 @ text @@ 1.1.4.2 log @Apply patches (requested by spz in ticket #1517): Update bind to 9.7.2-P3. @ text @a0 382 zkt-ls

zkt-ls

NAME
SYNOPSYS
DESCRIPTION
GENERAL OPTIONS
COMMAND OPTIONS
SAMPLE USAGE
ENVIRONMENT VARIABLES
FILES
BUGS
AUTHORS
COPYRIGHT
SEE ALSO

NAME

zkt−ls — list dnskeys

SYNOPSYS

zkt−ls −H

zkt−ls [−V|--view view] [−c file] [−l list] [−adefhkLprtz] [{keyfile|dir} ...]

zkt−ls −T [−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]
zkt−ls −−list-trustedkeys
[−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]

zkt−ls −K [−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]
zkt−ls −−list-dnskeys
[−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]

DESCRIPTION

The zkt-ls command list all dnssec zone keys found in the given or predefined default directory. It is also possible to specify keyfiles (K*.key) as arguments. With option −r subdirectories will be searched recursively and all dnssec keys found are listed, sorted by domain name, key type and generation time. In that mode the use of option −p may be helpful to find the location of the keyfile in the directory tree.

Other forms of the command, print out keys in a format suitable for a trusted-key section (−T) or as a DNSKEY (−K) resource record.

GENERAL OPTIONS

−V view, −−view=view

Try to read the default configuration out of a file named dnssec-<view>.conf . Instead of specifying the −V or --view option every time, it is also possible to create a hard or softlink to the executable file to give it an additional name like zkt-ls-<view> .

−c file, −−config=file

Read default values from the specified config file. Otherwise the default config file is read or build in defaults will be used.

−O optstr, −−config-option=optstr

Set any config file option via the commandline. Several config file options could be specified at the argument string but have to be delimited by semicolon (or newline).

−l list, −−label=list

Print out information solely about domains given in the comma or space separated list. Take care of, that every domain name has a trailing dot.

−d, −−directory

Skip directory arguments. This will be useful in combination with wildcard arguments to prevent dnsssec-zkt to list all keys found in subdirectories. For example "zkt-ls -d *" will print out a list of all keys only found in the current directory. Maybe it is easier to use "zkt-ls ." instead (without -r set). The option works similar to the −d option of ls(1).

−L, −−left-justify

Print out the domain name left justified.

−k, −−ksk

Select and print key signing keys only (default depends on command mode).

−z, −−zsk

Select and print zone signing keys only (default depends on command mode).

−r, −−recursive

Recursive mode (default is off).
Also settable in the dnssec.conf file (Parameter: Recursive).

−p, −−path

Print pathname in listing mode. In -C mode, don’t create the new key in the same directory as (already existing) keys with the same label.

−a, −−age

Print age of key in weeks, days, hours, minutes and seconds (default is off).
Also settable in the dnssec.conf file (Parameter: PrintAge).

−f, −−lifetime

Print the key lifetime.

−e, −−exptime

Print the key expiration time.

−t, −−time

Print the key generation time (default is on).
Also settable in the dnssec.conf file (Parameter: PrintTime).

−h

No header or trusted-key section header and trailer in -T mode

COMMAND OPTIONS

−H, −−help

Print out the online help.

−T, −−list-trustedkeys

List all key signing keys as a named.conf trusted-key section. Use −h to supress the section header/trailer.

−K, −−list-dnskeys

List the public part of all the keys in DNSKEY resource record format. Use −h to suppress comment lines.

SAMPLE USAGE

zkt−ls −r .

Print out a list of all zone keys found below the current directory.

zkt−ls −Z −c ""

Print out the compiled in default parameters.

zkt−ls −T ./zonedir/example.net

Print out a trusted-key section containing the key signing keys of "example.net".

zkt−ls --view intern

Print out a list of all zone keys found below the directory where all the zones of view intern live. There should be a seperate dnssec config file dnssec-intern.conf with a directory option to take affect of this.

zkt−ls−intern

Same as above. The binary file zkt−ls has another link, named zkt−ls−intern made, and zkt−ls examines argv[0] to find a view whose zones it proceeds to process.

ENVIRONMENT VARIABLES

ZKT_CONFFILE

Specifies the name of the default global configuration files.

FILES

/var/named/dnssec.conf

Built-in default global configuration file. The name of the default global config file is settable via the environment variable ZKT_CONFFILE.

/var/named/dnssec-<view>.conf

View specific global configuration file.

./dnssec.conf

Local configuration file (only used in −C mode).

BUGS

Some of the general options will not be meaningful in all of the command modes.
The option −l and the ksk rollover options insist on domain names ending with a dot.

AUTHORS

Holger Zuleger

COPYRIGHT

Copyright (c) 2005 − 2010 by Holger Zuleger. Licensed under the BSD Licences. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), rndc(8), named.conf(5), zkt-conf(8), zkt-keyman(8), zkt-signer(8)
RFC4641 "DNSSEC Operational Practices" by Miek Gieben and Olaf Kolkman,
DNSSEC HOWTO Tutorial by Olaf Kolkman, RIPE NCC
(http://www.nlnetlabs.nl/dnssec_howto/)


@ 1.1.2.1 log @Apply patches (requested by spz in ticket #1517): Update bind to 9.7.2-P3. @ text @a0 382 zkt-ls

zkt-ls

NAME
SYNOPSYS
DESCRIPTION
GENERAL OPTIONS
COMMAND OPTIONS
SAMPLE USAGE
ENVIRONMENT VARIABLES
FILES
BUGS
AUTHORS
COPYRIGHT
SEE ALSO

NAME

zkt−ls — list dnskeys

SYNOPSYS

zkt−ls −H

zkt−ls [−V|--view view] [−c file] [−l list] [−adefhkLprtz] [{keyfile|dir} ...]

zkt−ls −T [−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]
zkt−ls −−list-trustedkeys
[−V|--view view] [−c file] [−l list] [−dhrz] [{keyfile|dir} ...]

zkt−ls −K [−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]
zkt−ls −−list-dnskeys
[−V|--view view] [−c file] [−l list] [−dhkrz] [{keyfile|dir} ...]

DESCRIPTION

The zkt-ls command list all dnssec zone keys found in the given or predefined default directory. It is also possible to specify keyfiles (K*.key) as arguments. With option −r subdirectories will be searched recursively and all dnssec keys found are listed, sorted by domain name, key type and generation time. In that mode the use of option −p may be helpful to find the location of the keyfile in the directory tree.

Other forms of the command, print out keys in a format suitable for a trusted-key section (−T) or as a DNSKEY (−K) resource record.

GENERAL OPTIONS

−V view, −−view=view

Try to read the default configuration out of a file named dnssec-<view>.conf . Instead of specifying the −V or --view option every time, it is also possible to create a hard or softlink to the executable file to give it an additional name like zkt-ls-<view> .

−c file, −−config=file

Read default values from the specified config file. Otherwise the default config file is read or build in defaults will be used.

−O optstr, −−config-option=optstr

Set any config file option via the commandline. Several config file options could be specified at the argument string but have to be delimited by semicolon (or newline).

−l list, −−label=list

Print out information solely about domains given in the comma or space separated list. Take care of, that every domain name has a trailing dot.

−d, −−directory

Skip directory arguments. This will be useful in combination with wildcard arguments to prevent dnsssec-zkt to list all keys found in subdirectories. For example "zkt-ls -d *" will print out a list of all keys only found in the current directory. Maybe it is easier to use "zkt-ls ." instead (without -r set). The option works similar to the −d option of ls(1).

−L, −−left-justify

Print out the domain name left justified.

−k, −−ksk

Select and print key signing keys only (default depends on command mode).

−z, −−zsk

Select and print zone signing keys only (default depends on command mode).

−r, −−recursive

Recursive mode (default is off).
Also settable in the dnssec.conf file (Parameter: Recursive).

−p, −−path

Print pathname in listing mode. In -C mode, don’t create the new key in the same directory as (already existing) keys with the same label.

−a, −−age

Print age of key in weeks, days, hours, minutes and seconds (default is off).
Also settable in the dnssec.conf file (Parameter: PrintAge).

−f, −−lifetime

Print the key lifetime.

−e, −−exptime

Print the key expiration time.

−t, −−time

Print the key generation time (default is on).
Also settable in the dnssec.conf file (Parameter: PrintTime).

−h

No header or trusted-key section header and trailer in -T mode

COMMAND OPTIONS

−H, −−help

Print out the online help.

−T, −−list-trustedkeys

List all key signing keys as a named.conf trusted-key section. Use −h to supress the section header/trailer.

−K, −−list-dnskeys

List the public part of all the keys in DNSKEY resource record format. Use −h to suppress comment lines.

SAMPLE USAGE

zkt−ls −r .

Print out a list of all zone keys found below the current directory.

zkt−ls −Z −c ""

Print out the compiled in default parameters.

zkt−ls −T ./zonedir/example.net

Print out a trusted-key section containing the key signing keys of "example.net".

zkt−ls --view intern

Print out a list of all zone keys found below the directory where all the zones of view intern live. There should be a seperate dnssec config file dnssec-intern.conf with a directory option to take affect of this.

zkt−ls−intern

Same as above. The binary file zkt−ls has another link, named zkt−ls−intern made, and zkt−ls examines argv[0] to find a view whose zones it proceeds to process.

ENVIRONMENT VARIABLES

ZKT_CONFFILE

Specifies the name of the default global configuration files.

FILES

/var/named/dnssec.conf

Built-in default global configuration file. The name of the default global config file is settable via the environment variable ZKT_CONFFILE.

/var/named/dnssec-<view>.conf

View specific global configuration file.

./dnssec.conf

Local configuration file (only used in −C mode).

BUGS

Some of the general options will not be meaningful in all of the command modes.
The option −l and the ksk rollover options insist on domain names ending with a dot.

AUTHORS

Holger Zuleger

COPYRIGHT

Copyright (c) 2005 − 2010 by Holger Zuleger. Licensed under the BSD Licences. There is NO warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.

SEE ALSO

dnssec-keygen(8), dnssec-signzone(8), rndc(8), named.conf(5), zkt-conf(8), zkt-keyman(8), zkt-signer(8)
RFC4641 "DNSSEC Operational Practices" by Miek Gieben and Olaf Kolkman,
DNSSEC HOWTO Tutorial by Olaf Kolkman, RIPE NCC
(http://www.nlnetlabs.nl/dnssec_howto/)


@