ldns-dane(1) General Commands Manual ldns-dane(1) (NAME) ldns-dane - TLS DANE (RFC6698) (SYNOPSIS) ldns-dane [OPTIONS] verify name port ldns-dane [OPTIONS] -t tlsafile verify ldns-dane [OPTIONS] create name port [ Certificate-usage [ Selector [ Matching-type ] ] ] ldns-dane -h ldns-dane -v (DESCRIPTION) : TLS name:port . () TLSA name . : () TLSA tlsafile TLS . : TLS name:port () TLSA . (rr) TLSA : Certificate-usage: 0 | PKIX-TA (CA constraint) 1 | PKIX-EE (Service certificate constraint) 2 | DANE-TA (Trust anchor assertion) 3 | DANE-EE () Selector: 0 | Cert 1 | SPKI SubjectPublicKeyInfo () Matching-type: 0 | Full 1 | SHA2-256 SHA-256 () 2 | SHA2-512 SHA-512 (OPTIONS) -4 TLS IPv4. -6 TLS IPv6. -a address name address . . -b "name. TYPE52 \# size hexdata" TLSA. -c certfile TLS name:port ( ) certfile ( TLSA ). -d DNSSEC TLSA (insecure) (bogus) . -f CAfile CAfile . -h . -i . -k keyfile DNSKEY DS . () ( -S) . . -k (/etc/trusted-key.key) DNSKEY DS . -n . -o offset TLSA << >> (Trust anchor assertion) offset . 0 1 2 . offset -1 () ( 0) (self-signed) . () ( DANE ). -p CApath CApath . -s TLSA << CA>> << >> PKIX . << CA>> . -S () . DNSSEC ( AD ). -t tlsafile () TLSA tlsafile. name port TLSA name port transport . () TLSA name port transport . -T PKIX () TLSA . -u UDP TCP. -v . (FILES) /etc/trusted-key.key -k . (SEE ALSO) unbound-anchor(8) (AUTHORS) ldns ldns. (REPORTING BUGS) . (COPYRIGHT) (C) 2012 NLnet Labs. . . 17 September 2012 ldns-dane(1)