diff --git a/doc/man/knot.conf.5in b/doc/man/knot.conf.5in
index 62393b6a28cf5fe613118ea487efc9b5ddb30a73..408fefaa8b7bcc03521b54c43c34e64dba8fd5b2 100644
--- a/doc/man/knot.conf.5in
+++ b/doc/man/knot.conf.5in
@@ -510,7 +510,7 @@ policy:
     nsec3: BOOL
     nsec3\-iterations: INT
     nsec3\-salt\-length: INT
-    nsec3\-resalt: TIME
+    nsec3\-salt\-lifetime: TIME
     propagation\-delay: TIME
 .ft P
 .fi
@@ -581,7 +581,7 @@ A length of a salt field in octets, which is appended to the original owner
 name before hashing.
 .sp
 \fIDefault:\fP 8
-.SS nsec3\-resalt
+.SS nsec3\-salt\-lifetime
 .sp
 A validity period of newly issued salt field.
 .sp
diff --git a/doc/reference.rst b/doc/reference.rst
index 15b863b3795954750a0f42313e3305d85e93d9f1..16491fe290305c4efbd98a10831783441f87d2d0 100644
--- a/doc/reference.rst
+++ b/doc/reference.rst
@@ -576,7 +576,7 @@ DNSSEC policy configuration.
      nsec3: BOOL
      nsec3-iterations: INT
      nsec3-salt-length: INT
-     nsec3-resalt: TIME
+     nsec3-salt-lifetime: TIME
      propagation-delay: TIME
 
 .. _policy_id:
@@ -696,10 +696,10 @@ name before hashing.
 
 *Default:* 8
 
-.. _policy_nsec3-resalt:
+.. _policy_nsec3-salt-lifetime:
 
-nsec3-resalt
-------------
+nsec3-salt-lifetime
+-------------------
 
 A validity period of newly issued salt field.
 
diff --git a/src/knot/conf/scheme.h b/src/knot/conf/scheme.h
index 87116adcaeda27ddb396a7663ee4cc1a4d228886..963763a90558bf64ef5e6995ef73629f493ec9d3 100644
--- a/src/knot/conf/scheme.h
+++ b/src/knot/conf/scheme.h
@@ -83,7 +83,7 @@
 #define C_REQUEST_EDNS_OPTION	"\x13""request-edns-option"
 #define C_RMT			"\x06""remote"
 #define C_RRSIG_LIFETIME	"\x0E""rrsig-lifetime"
-#define C_RRSIG_REFRESH		"\x14""rrsig-refresh-before"
+#define C_RRSIG_REFRESH		"\x0D""rrsig-refresh"
 #define C_RUNDIR		"\x06""rundir"
 #define C_SECRET		"\x06""secret"
 #define C_SEM_CHECKS		"\x0F""semantic-checks"