dnssec-checkds — DNSSEC delegation consistency checking tool
dnssec-checkds verifies the correctness of Delegation Signer (DS) or DNSSEC Lookaside Validation (DLV) resource records for keys in a specified zone.
Specify a digest algorithm to use when converting the zone's DNSKEY records to expected DS or DLV records. This option can be repeated, so that multiple records are checked for each DNSKEY record.
algorithm must be one of
SHA-1, SHA-256, or SHA-384. These values are case insensitive,
and the hyphen may be omitted. If no algorithm is specified,
the default is SHA-256.
file is specified, then the zone is
read from that file to find the DNSKEY records. If not,
then the DNSKEY records for the zone are looked up in the DNS.
Check for a DLV record in the specified lookaside domain, instead of checking for a DS record in the zone's parent.
Specifies a prepared dsset file, such as would be generated by dnssec-signzone, to use as a source for the DS RRset instead of querying the parent.
Specifies a path to a dig binary. Used for testing.
Specifies a path to a dnssec-dsfromkey binary. Used for testing.
BIND 9.15.2 (Development Release)