sq-network-dane - Man Page

Retrieve and publishes certificates via DANE

Synopsis

sq network dane search [OPTIONS] ADDRESS
sq network dane generate [OPTIONS]  

Description

Retrieve and publishes certificates via DANE.

DNS-Based Authentication of Named Entities (DANE) is a method for publishing and retrieving certificates in DNS as specified in RFC 7929.

Subcommands

sq network dane generate

Generate DANE records for the given domain and certs.

The certificates are minimized, and one record per email address is emitted.  If multiple user IDs map to one email address, then all matching user IDs are included in the emitted certificates.

By default, OPENPGPKEY resource records are emitted.  If your DNS server doesn't understand those, use `--type generic` to emit generic records instead.

Examples

sq network dane generate

Generate DANE records from juliet.pgp for example.org.

    sq network dane generate --domain=example.org \
    --file=juliet.pgp

Generate DANE records for all certs with an authenticated user ID in example.org.

    sq network dane generate --domain=example.org --all

See Also

sq(1), sq-network(1), sq-network-dane-search(1), sq-network-dane-generate(1).

For the full documentation see <https://book.sequoia-pgp.org>.

Version

0.39.0 (sequoia-openpgp 1.21.2)

Referenced By

sq-network(1), sq-network-dane-generate(1), sq-network-dane-search(1).

0.39.0 Sequoia PGP