xref: /netbsd-src/external/mpl/bind/dist/bin/dnssec/dnssec-revoke.rst (revision f0fde9902fd4d72ded2807793acc7bfaa1ebf243)
1..
2   Copyright (C) Internet Systems Consortium, Inc. ("ISC")
3
4   This Source Code Form is subject to the terms of the Mozilla Public
5   License, v. 2.0. If a copy of the MPL was not distributed with this
6   file, you can obtain one at https://mozilla.org/MPL/2.0/.
7
8   See the COPYRIGHT file distributed with this work for additional
9   information regarding copyright ownership.
10
11..
12   Copyright (C) Internet Systems Consortium, Inc. ("ISC")
13
14   This Source Code Form is subject to the terms of the Mozilla Public
15   License, v. 2.0. If a copy of the MPL was not distributed with this
16   file, You can obtain one at http://mozilla.org/MPL/2.0/.
17
18   See the COPYRIGHT file distributed with this work for additional
19   information regarding copyright ownership.
20
21
22.. highlight: console
23
24.. _man_dnssec-revoke:
25
26dnssec-revoke - set the REVOKED bit on a DNSSEC key
27---------------------------------------------------
28
29Synopsis
30~~~~~~~~
31
32:program:`dnssec-revoke` [**-hr**] [**-v** level] [**-V**] [**-K** directory] [**-E** engine] [**-f**] [**-R**] {keyfile}
33
34Description
35~~~~~~~~~~~
36
37``dnssec-revoke`` reads a DNSSEC key file, sets the REVOKED bit on the
38key as defined in :rfc:`5011`, and creates a new pair of key files
39containing the now-revoked key.
40
41Options
42~~~~~~~
43
44``-h``
45   This option emits a usage message and exits.
46
47``-K directory``
48   This option sets the directory in which the key files are to reside.
49
50``-r``
51   This option indicates to remove the original keyset files after writing the new keyset files.
52
53``-v level``
54   This option sets the debugging level.
55
56``-V``
57   This option prints version information.
58
59``-E engine``
60   This option specifies the cryptographic hardware to use, when applicable.
61
62   When BIND 9 is built with OpenSSL, this needs to be set to the OpenSSL
63   engine identifier that drives the cryptographic accelerator or
64   hardware service module (usually ``pkcs11``). When BIND is
65   built with native PKCS#11 cryptography (``--enable-native-pkcs11``), it
66   defaults to the path of the PKCS#11 provider library specified via
67   ``--with-pkcs11``.
68
69``-f``
70   This option indicates a forced overwrite and causes ``dnssec-revoke`` to write the new key pair,
71   even if a file already exists matching the algorithm and key ID of
72   the revoked key.
73
74``-R``
75   This option prints the key tag of the key with the REVOKE bit set, but does not
76   revoke the key.
77
78See Also
79~~~~~~~~
80
81:manpage:`dnssec-keygen(8)`, BIND 9 Administrator Reference Manual, :rfc:`5011`.
82