Bug 449287

Summary: dns-keygen undocumented and unhelpful
Product: [Fedora] Fedora Reporter: Jay Levitt <jay>
Component: bindAssignee: Adam Tkac <atkac>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: 9CC: atkac, jay, ovasik
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-06-02 12:17:27 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Jay Levitt 2008-06-01 20:04:00 UTC
Description of problem:

The sample file /usr/share/doc/bind-9.5.0/sample/etc/named.conf includes the
following section:

key ddns_key
{
	algorithm hmac-md5;
	secret "use /usr/sbin/dns-keygen to generate TSIG keys";
};

However, there is no man page for dns-keygen, and it does not respond to -h or
--help options.  I suspect it *may* be obsolete now that bind comes with
dnssec-keygen.  No matter what arguments I give it, it spits out an encrypted
string.  Talk about secure!  (Yeah, I know, it's an MD5 hash, apparently salted.)

Version-Release number of selected component (if applicable):
9.5.0-29.b2.fc9

Suggested fix:

Either 

1. Remove dns-keygen from the package, OR

2a. Add a manpage
2b. Add -h/--help options

Comment 1 Adam Tkac 2008-06-02 12:17:27 UTC
That executable is not part of upstream distribution, we only used it to
generate /etc/rndc.key file. That file is now generated with rndc-confgen -a
utility and dns-keygen is removed.

Fixed in rawhide, I'm not going to fix it in F9. If you want this fixed also in
F9 please reopen this bug. Thanks for your report