Next: , Previous: , Up: zones Statement Definition and Grammar   [Contents][Index]


A.7.2.18 signature-lifetime

Specifies how long should the automatically generated DNSSEC signatures be valid. Expiration will thus be set as current time (in the moment of signing) + signature-lifetime. Possible values are from 10801 to INT_MAX. The lower limit is because the server will trigger resign when any of the signatures expires in 7200 seconds or less and it was chosen as a reasonable value with regard to signing overhead. Setting the signature lifetime to minimum value will result in re-signing the zone each hour. For information about zone expiration date, invoke the knotc zonestatus command.

Default value: 30d (2592000)