#!/bin/bash # NSC -- DNSSEC key delegation # (c) 2019 Martin Mares set -e shopt -s nullglob . bin/shell-env if [ $# -ne 1 ] ; then echo >&2 "Usage: $0 " exit 1 fi Z=$1 >dss/$Z.new for K in keys/$Z/*.key ; do B=$(basename $K .key) if grep -q '; This is a key-signing key,' $K ; then echo "** $B: Adding" dnssec-dsfromkey $DSFROMKEY_OPTIONS $K >>dss/$Z.new else echo "-- $B: Not a KSK" fi done mv dss/$Z.new dss/$Z