2013-01-01ISCInternet Systems Consortium, Inc.dnssec-checkds8BIND9dnssec-checkdsDNSSEC delegation consistency checking tool20122013201420152016201720182019Internet Systems Consortium, Inc. ("ISC")dnssec-checkdszoneDESCRIPTIONdnssec-checkds
verifies the correctness of Delegation Signer (DS)
resource records for keys in a specified zone.
OPTIONS-a algorithm
Specify a digest algorithm to use when converting the
zone's DNSKEY records to expected DS records. This
option can be repeated, so that multiple records are
checked for each DNSKEY record.
The algorithm must be one of
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
and the hyphen may be omitted. If no algorithm is specified,
the default is SHA-256.
-f file
If a is specified, then the zone is
read from that file to find the DNSKEY records. If not,
then the DNSKEY records for the zone are looked up in the DNS.
-s file
Specifies a prepared dsset file, such as would be generated
by dnssec-signzone, to use as a source for
the DS RRset instead of querying the parent.
-d dig path
Specifies a path to a dig binary. Used
for testing.
-D dsfromkey path
Specifies a path to a dnssec-dsfromkey binary.
Used for testing.
SEE ALSOdnssec-dsfromkey8,
dnssec-keygen8,
dnssec-signzone8,