Lines Matching full:anchor

1 .TH "unbound-anchor" "8" "Jul 16, 2025" "NLnet Labs" "unbound 1.23.1"
3 .\" unbound-anchor.8 -- unbound anchor maintenance utility manual
11 .B unbound\-anchor
12 \- Unbound anchor utility.
14 .B unbound\-anchor
17 .B Unbound\-anchor
18 performs setup or update of the root trust anchor for DNSSEC validation.
19 The program fetches the trust anchor with the method from RFC7958 when
28 # provide or update the root anchor (if necessary)
29 unbound-anchor \-a "/var/unbound/root.key"
30 # Please note usage of this root anchor is at your own risk
35 # auto-trust-anchor-file: "/var/unbound/root.key"
39 This tool provides builtin default contents for the root anchor and root
42 It tests if the root anchor file works, and if not, and an update is possible,
43 attempts to update the root anchor using the root update certificate.
45 if all checks are successful, it updates the root anchor file. Otherwise
46 the root anchor file is unchanged. It performs RFC5011 tracking if the
55 The root anchor key file, that is read in and written out.
86 signature over the xml file, using the pem file (\-c) as trust anchor.
113 hints is used. Unbound\-anchor goes to the network itself for these roots,
128 errors by default; in that case the original root anchor file is simply
138 Debug option to force update of the root anchor through downloading the xml
148 This tool exits with value 1 if the root anchor was updated using the
149 certificate or if the builtin root-anchor was used. It exits with code
155 unbound-anchor \-a "root.key" || logger "Please check root.key"
165 By running "unbound\-anchor \-l" the keys and certificate that are
173 The root anchor file, updated with 5011 tracking, and read and written to.
178 DNSSEC root trust anchor. You can update it by fetching it from