summaryrefslogtreecommitdiff
path: root/1-make-anchor.sh
blob: 9d04655fe441cac7c6c7596cc3f0201fda4df1f9 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
#!/bin/bash

cd work

# Generate a key that will be used to sign the keys
# In out scenatio this will be used as a trusted root
dnssec-keygen -f KSK -a ECDSA384 -b 4096 -n ZONE .
cp *.key ../anchor.key
dnssec-dsfromkey *.key > ../anchor.ds

# Generate a key that will be used to sign records
dnssec-keygen -a ECDSA384 -b 4096 -n ZONE .