etc/services - sync with NetBSD-8
[minix.git] / external / bsd / bind / dist / contrib / zkt-1.1.3 / examples / flat / dnssec.conf
blob53849784158bd4d3ff57145b65d49fff293573f3
1 #   
2 #       @(#) dnssec.conf T1.0rc1 (c) Feb 2005 - Mar 2010 Holger Zuleger hznet.de
3 #   
5 #   dnssec-zkt options
6 Zonedir:        "."
7 Recursive:      True
8 PrintTime:      False
9 PrintAge:       True
10 LeftJustify:    False
12 #   zone specific values
13 ResignInterval: 2d      # (172800 seconds)
14 Sigvalidity:    6d      # (518400 seconds)
15 Max_TTL:        8h      # (28800 seconds)
16 Propagation:    5m      # (300 seconds)
17 KEY_TTL:        1h      # (3600 seconds)
18 Serialformat:   incremental
20 #   signing key parameters
21 Key_Algo:       RSASHA512
22 KSK_lifetime:   60d     # (5184000 seconds)
23 KSK_bits:       1300
24 KSK_randfile:   "/dev/urandom"
25 ZSK_lifetime:   2w      # (1209600 seconds)
26 ZSK_bits:       1024
27 ZSK_randfile:   "/dev/urandom"
28 SaltBits:       24
30 #   dnssec-signer options
31 LogFile:        "zkt.log"
32 LogLevel:       DEBUG
33 LogDomainDir:   "."
34 SyslogFacility: USER
35 SyslogLevel:    NOTICE
36 VerboseLog:     2
37 Keyfile:        "dnskey.db"
38 Zonefile:       "zone.db"
39 KeySetDir:      "../keysets"
40 DLV_Domain:     ""
41 Sig_Pseudorand: True
42 Sig_GenerateDS: True
43 Sig_DnsKeyKSK:  False
44 Sig_Parameter:  "-n 1"
45 Distribute_Cmd: "./dist.sh"