Keys

TSIG (Transfer Signature) keys limit what hosts are allowed to synchronize zone files from the primary server. This page displays the keys currently used by DNS Server.

To create a new key:

  1. Click Create.
  2. Select Create key.
  3. Enter a key name and select an algorithm. DNS Server supports HMAC-MD5 and HMAC-SHA512 keys.
  4. Click Save to create the key.

To export a key:

Keys can be exported to a local computer.

  1. Select the key you wish to export.
  2. Click Export Key.

To import a key:

Keys can be imported from a local computer and added to the list of usable keys.

  1. Click Create.
  2. Select Import key.
  3. Choose a key file on the local computer and click Save.

To delete a key:

  1. Select the key you wish to delete.
  2. Click Delete.

Key file format rules:

  • Implement the key statement format of Bind9.
  • Key names can include 63 Unicode characters, including letters, numbers, and the following symbols: dashes (-), underscores (_), and dots (.). The name "rndc-key" is reserved for system use.
  • Use an HMAC-MD5 or HMAC-SHA512 encryption algorithm.