OpenBSD Handbook

OpenBSD 7.9 release · amd64 · Generated 2026-09-09

zkt-1.1.6

DNSsec Zone Key Tool

Back to search · Project homepage

Description

ZKT (Zone Key Tool) manages keys and signatures for DNSSEC-zones. It consists of four commands: zkt-conf, to manage the config file zkt-ls, to list dnssec zone keys zkt-keyman, to manage dnssec zone keys manually (seldom used) zkt-signer, to sign a zone and manage the lifetime and rollover of the zone signing keys Most of the commands are simple wrapper commands around BIND's dnssec-keygen(8) and dnssec-signzone(8) commands. Warning: ZKT is old and doesn't seem to be very actively maintained - it might not work with current versions of BIND tools. Users looking to setup DNSSEC should look elsewhere, either higher-level tools like opendnssec or the built-in support in PowerDNS authoritative server, or using lower-level tools directly (dnssec-signzone from the isc-bind package or ldns-signzone from the ldns-utils package).

Package information

Ports path
security/zkt
Package architecture
amd64
Maintainer
The OpenBSD ports mailing-list <ports@openbsd.org>
Categories
security
Available flavors
None listed

These are ports metadata. Binary availability depends on the release, architecture and mirror. Build and test dependencies are not an installation checklist.

Direct dependencies

Runtime

Build

Installing and updating packages · Package details as JSON