|
Commands Used |
Purpose |
|---|---|
|
|
Create the Utimaco binary directory. |
|
|
Create the Utimaco library directory. |
|
|
Copy the Utimaco PKCS#11 library to the target location. |
|
|
Change to the SecurityServer installation directory. |
|
|
Copy Utimaco administration utilities. |
|
|
Make the utilities executable. |
|
|
Navigate to the PKCS#11 sample configuration directory. |
|
|
Copy the PKCS#11 configuration file. |
|
|
Change to the Bind9 working directory. |
|
|
Set the PKCS#11 configuration environment variable. |
|
|
Create and initialize an HSM token/slot. |
|
|
Initialize the Security Officer PIN. |
|
|
Verify the installed OpenSSL version. |
|
|
Verify the installed OpenSSL providers, including PKCS#11 provider. |
|
|
Extract the Bind9 source package. |
|
|
Generate the configure scripts for Bind9 build. |
|
|
Install Bind9 build dependencies. |
|
|
Configure the Bind9 build environment. |
|
|
Build Bind9 from source. |
|
|
Install the compiled Bind9 software. |
|
|
Check the installed Bind9 version. |
|
|
Start the Bind9 DNS service. |
|
|
Generate an RSA KSK on the HSM. |
|
|
Generate an RSA ZSK on the HSM. |
|
|
List objects stored in RSA slot. |
|
|
Generate an ECC KSK on the HSM. |
|
|
Generate an ECC ZSK on the HSM. |
|
|
List objects stored in ECC slot. |
|
|
Generate a Bind9 reference key file for RSA KSK. |
|
|
Generate a Bind9 reference key file for RSA ZSK. |
|
|
List generated key files. |
|
|
Generate a Bind9 reference key file for ECC KSK. |
|
|
Generate a Bind9 reference key file for ECC ZSK. |
|
|
Sign a DNS zone using RSA keys. |
|
|
Verify a signed RSA zone file. |
|
|
Sign a DNS zone using ECC keys. |
|
|
Verify a signed ECC zone file. |
|
|
Edit the Bind9 configuration file. |
|
|
Start Bind9 with DNSSEC-enabled configuration. |
|
|
Verify the re-signed DNS zone after key rollover. |
CLI Commands