Sophie

Sophie

distrib > Mageia > 4 > x86_64 > by-pkgid > a80c2a17c20d38e6a349bb777eb92ba4 > files > 55

pdns-3.3.2-1.mga4.x86_64.rpm

<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml"><head><meta http-equiv="Content-Type" content="text/html; charset=UTF-8" /><title>7. Operational instructions</title><link rel="stylesheet" href="docbook.css" type="text/css" /><meta name="generator" content="DocBook XSL Stylesheets V1.75.2" /><link rel="home" href="index.html" title="PowerDNS manual" /><link rel="up" href="powerdnssec-auth.html" title="Chapter 12. Serving authoritative DNSSEC data" /><link rel="prev" href="dnssec-advice-precautions.html" title="6. DNSSEC advice &amp; precautions" /><link rel="next" href="dnssec-modes.html" title="8. Modes of operation" /></head><body><div class="navheader"><table width="100%" summary="Navigation header"><tr><th colspan="3" align="center">7. Operational instructions</th></tr><tr><td width="20%" align="left"><a accesskey="p" href="dnssec-advice-precautions.html">Prev</a> </td><th width="60%" align="center">Chapter 12. Serving authoritative DNSSEC data</th><td width="20%" align="right"> <a accesskey="n" href="dnssec-modes.html">Next</a></td></tr></table><hr /></div><div class="section" title="7. Operational instructions"><div class="titlepage"><div><div><h2 class="title" style="clear: both"><a id="dnssec-operational-doctrine"></a>7. Operational instructions</h2></div></div></div><div class="toc"><dl><dt><span class="section"><a href="dnssec-operational-doctrine.html#publish-ds">7.1. Publishing a DS</a></span></dt><dt><span class="section"><a href="dnssec-operational-doctrine.html#zsk-rollover">7.2. ZSK rollover</a></span></dt><dt><span class="section"><a href="dnssec-operational-doctrine.html#ksk-rollover">7.3. KSK rollover</a></span></dt><dt><span class="section"><a href="dnssec-operational-doctrine.html#going-insecure">7.4. Going insecure</a></span></dt><dt><span class="section"><a href="dnssec-operational-doctrine.html#nsec3-change">7.5. NSEC(3) change</a></span></dt></dl></div><p>
  In this chapter various DNSSEC transitions are discussed, and how to execute them within PowerDNSSEC.
  </p><div class="section" title="7.1. Publishing a DS"><div class="titlepage"><div><div><h3 class="title"><a id="publish-ds"></a>7.1. Publishing a DS</h3></div></div></div><p>
  To publish a DS to a parent zone, utilize 'pdnssec show-zone' and take the DS from its output, and transfer it securely
  to your parent zone.
  </p></div><div class="section" title="7.2. ZSK rollover"><div class="titlepage"><div><div><h3 class="title"><a id="zsk-rollover"></a>7.2. ZSK rollover</h3></div></div></div><p>
  .. pdnssec activate-zone-key ZONE next-key-id ..
  .. pdnssec deactivate-zone-key ZONE prev-key-id ..
  .. pdnssec remove-zone-key ZONE prev-key-id ..
  </p></div><div class="section" title="7.3. KSK rollover"><div class="titlepage"><div><div><h3 class="title"><a id="ksk-rollover"></a>7.3. KSK rollover</h3></div></div></div><p>
  .. pdnssec add-zone-key ZONE ksk ..
  .. pdnssec show-zone ZONE and communicate duplicate DS ..
  .. pdnssec activate-zone-key ZONE next-key-id ..
  .. pdnssec deactivate-zone-key ZONE prev-key-id ..
  .. pdnssec remove-zone-key ZONE prev-key-id ..
  </p></div><div class="section" title="7.4. Going insecure"><div class="titlepage"><div><div><h3 class="title"><a id="going-insecure"></a>7.4. Going insecure</h3></div></div></div><p>
  .. pdnssec disable-dnssec ..
  </p></div><div class="section" title="7.5. NSEC(3) change"><div class="titlepage"><div><div><h3 class="title"><a id="nsec3-change"></a>7.5. NSEC(3) change</h3></div></div></div><p>This section describes how to change NSEC(3) parameters when they are already set.</p><div class="warning" title="Warning" style="margin-left: 0.5in; margin-right: 0.5in;"><table border="0" summary="Warning"><tr><td rowspan="2" align="center" valign="top" width="25"><img alt="[Warning]" src="warning.png" /></td><th align="left">Warning</th></tr><tr><td align="left" valign="top"><p>The following instructions might not be correct or complete!</p></td></tr></table></div><p>
    .. pdnssec set-nsec3 ZONE 'parameters'
    .. pdnssec show-zone ZONE and communicate duplicate DS ..
  </p><p>
    For further details, please see <a class="xref" href="pdnssec.html" title="5. 'pdnssec' for PowerDNSSEC command &amp; control">Section 5, “'pdnssec' for PowerDNSSEC command &amp; control”</a>.
  </p></div></div><div class="navfooter"><hr /><table width="100%" summary="Navigation footer"><tr><td width="40%" align="left"><a accesskey="p" href="dnssec-advice-precautions.html">Prev</a> </td><td width="20%" align="center"><a accesskey="u" href="powerdnssec-auth.html">Up</a></td><td width="40%" align="right"> <a accesskey="n" href="dnssec-modes.html">Next</a></td></tr><tr><td width="40%" align="left" valign="top">6. DNSSEC advice &amp; precautions </td><td width="20%" align="center"><a accesskey="h" href="index.html">Home</a></td><td width="40%" align="right" valign="top"> 8. Modes of operation</td></tr></table></div></body></html>