mirror of
https://github.com/coredns/coredns.git
synced 2025-11-01 18:53:43 -04:00
Update README.md
This commit is contained in:
@@ -8,18 +8,18 @@
|
||||
dnssec [zones...]
|
||||
~~~
|
||||
|
||||
* `zones` zones that should be signed. If empty the zones from the configuration block
|
||||
* `zones` zones that should be signed. If empty, the zones from the configuration block
|
||||
are used.
|
||||
|
||||
If keys are not specified (see below) a key is generated and used for all signing operations. The
|
||||
DNSSEC signing will treat this key a CSK (common signing key) forgoing the ZSK/KSK split. All
|
||||
If keys are not specified (see below), a key is generated and used for all signing operations. The
|
||||
DNSSEC signing will treat this key a CSK (common signing key), forgoing the ZSK/KSK split. All
|
||||
signing operations are done online. Authenticated denial of existence is implemented with NSEC black
|
||||
lies. Using ECDSA as an algorithm is preferred as this leads to smaller signatures (compared to
|
||||
RSA).
|
||||
|
||||
A signing key can be specified by using the `key` directive.
|
||||
|
||||
WARNING: when a key is generated there is currently no way to extract any key material from CoreDNS,
|
||||
WARNING: when a key is generated there is currently no way to extract any key material from CoreDNS, as
|
||||
this key only lives in memory. See issue <https://github.com/miekg/coredns/issues/211>.
|
||||
|
||||
TODO(miek): think about key rollovers.
|
||||
@@ -31,7 +31,7 @@ dnssec [zones... ] {
|
||||
}
|
||||
~~~
|
||||
|
||||
* `key file` indicates key file(s) should be read from disk. When multiple keys are specified, RRset
|
||||
* `key file` indicates that key file(s) should be read from disk. When multiple keys are specified, RRsets
|
||||
will be signed with all keys. Generating a key can be done with `dnssec-keygen`: `dnssec-keygen -a
|
||||
ECDSAP256SHA256 <zonename>`. A key created for zone *A* can be safely used for zone *B*.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user