{"repo":"northox/dnssec-reverb","free":true,"listed":false,"github":"https://github.com/northox/dnssec-reverb","clone":"git clone https://github.com/northox/dnssec-reverb.git","description":"Automate DNSSEC key rotation for both ZSK and KSK","language":"Shell","stars":28,"topics":["dnssec","dnssecurity","key-management","automation","rotation"],"license":null,"category":"workflow-automation","readme_excerpt":"dnssec-reverb Shell script based DNSSEC key management tool I was looking for something that would take care of the rotation of my DNSSEC keys that wouldn't require many dependencies, was simple to manage and that I could actually trust - easily auditable. I found an unmaintained script called dnsseczonetool from @kfujiwara and refactor it to fit my needs. It is used and tested on OpenBSD but should work pretty much anywhere with the proper paths. Reverb is straightforward and couldn't be more trustable/easy to audit. Enjoy! Release notes CAUTION the latest release changed the serial special tag from '\\ SERIAL ' to '00001111' to ensure named/nsd compatibility. Update your master zone. Features Supports nsd and bind servers Supports ldns and bind's dnssec tools Should run on any unix-like systems&trade; Don't trust me, audit the code!&trade; KISS&reg; auto increment of the serial (date format) Requirements nsd or bind ldns from NLnet labs or bind's DNSSEC tools standard unix tools such as sed & awk Installation 1. Copy dnssec-reverb in a directory in your $PATH. $ sudo cp dnssec-reverb /usr/local/sbin/ 2. Create a configuration file. The config file will be searched in the following order 1) by looking at the $DNSSEC REVERB CONF environment variable, 2) within the same directory than the script ( dirname $0 ), 3) within /etc/ and finally 4) within /usr/local/etc/ . At the very least it must specify the master zone file directory using the MASTERDIR variable. Optionnaly, specif","default_branch":null,"files":null,"tree":[],"storefront":"/r/northox","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/northox/dnssec-reverb/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}