Previous: dnssec-keydir, Up: zones Statement Definition and Grammar [Contents][Index]
Specifies how long should the automatically generated DNSSEC signatures be valid. Expiration will thus be set as current time (in the moment of signing) + signature-lifetime
.
Possible values are from 7201 to INT_MAX. The lower limit is because the server will trigger resign when any of the signatures expires in 7200 seconds or less. For information about zone
expiration date, invoke the knotc zonestatus
command.
Default value: 30d (2592000)