Next: serial-policy, Previous: dnssec-enable, Up: zones Statement Definition and Grammar [Contents][Index]
Specifies how long should the automatically generated DNSSEC signatures be valid.
Expiration will thus be set as current time (in the moment of signing)
+ signature-lifetime
.
Possible values are from 10801 to INT_MAX. The lower limit is because the server
will trigger resign when any of the signatures expires in 7200 seconds or less
and it was chosen as a reasonable value with regard to signing overhead. Setting
the signature lifetime to minimum value will result in re-signing the zone each
hour. For information about zone expiration date, invoke the
knotc zonestatus
command.
Default value: 30d (2592000)