generate_host_keys.sh 284 B

123456789101112
  1. #!/bin/sh
  2. # According to https://en.wikipedia.org/wiki/TSIG HMAC-MD5 is not very secure.
  3. dnssec-keygen -a HMAC-SHA512 -b 512 -K ./keys/ -n HOST $1.
  4. KEY=$(awk '$1 == "Key:" {print $2}' K$1*.private)
  5. cat > keys/keys.conf <<EOF
  6. key $1. {
  7. algorithm HMAC-SHA512;
  8. secret "$KEY";
  9. };
  10. EOF