key (nrcmd)							key (nrcmd)

NAME
    key - Manage TSIG key objects

SYNOPSIS
    key list 
    key listnames
    key <name> show
    key <name> create <secret> [<attribute>=<value>...]
    key <name> delete
    key <name> get <attribute>
    key <name> set <attribute>=<value> [<attribute>=<value> ...]
    key <name> unset <attribute> 
    
    
DESCRIPTION
    The key command creates and manages transaction signature (TSIG)
    keys for DNS updates, zone transfers, queries, and recursions. 
    TSIG security, as defined in RFC 2845, enables both DNS and DHCP
    servers to authenticate DNS updates. TSIG security uses the 
    HMAC-MD5 (or keyed MD5) algorithm to generate a signature that 
    is used to authenticate the requests and responses. The DHCP 
    server uses TSIG keys to create TSIG resource records while 
    processing DNS updates.

    To configure TSIG security on a DHCP server, you must first 
    create a shared key, then enable DNS update for your scopes 
    by setting the dynamic-dns attribute to update-all). Also, 
    enable the dynamic-dns-tsig attribute for forward or reverse
    zones for the scope or on the server level. 

EXAMPLES

STATUS

SEE ALSO

PROPERTIES
  Attributes:

    algorithm[3] (AT_ENUMSTR(), Optional, default: hmac-md5)
        The algorithm that this key is used with.  Currently we only
        support hmac-md5.

    id[6] (AT_INT, Optional, default: <none>)
        Displays an integer id for the key.

    secret[2] (AT_KEY, Required, default: <none>)
        A base64 encoded string used for transaction authentication.

    security-type[4] (AT_ENUMSTR(), Optional, default: TSIG)
        The type of security that this key is going to be used for.
        Currently we only support TSIG keys.

    time-skew[5] (AT_RANGETIME, Optional, default: 5m)
        The time stamp fudge factor (amount that the time values can
        differ).

