Add dnssec-policy text for dnssec-importkey

You should not use dnssec-importkey to import DNSKEY records from
other providers (for example when setting up multi-signer).

Clarify this in the manpage.
This commit is contained in:
Matthijs Mekking 2025-10-08 09:44:54 +02:00
parent 8f392d484e
commit 4df536e0dc

View file

@ -40,6 +40,11 @@ possible to set publication (:option:`-P`) and deletion (:option:`-D`) times for
key, which means the public key can be added to and removed from the
DNSKEY RRset on schedule even if the true private key is stored offline.
When using ``dnssec-policy``, do not use :program:`dnssec-importkey` to
import key files that cannot be used for signing. In this case, simply publish the
imported DNSKEY record in the zone, and make sure that the files are outside
the configured ``key-directory``.
Options
~~~~~~~