/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to mandos-keygen.xml

  • Committer: Teddy Hogeborn
  • Date: 2008-09-21 13:42:34 UTC
  • Revision ID: teddy@fukt.bsnet.se-20080921134234-jo8p4rwtm50yb4xj
* clients.conf ([bar]/secfile): Do not imply armored format.

* debian/control: Build-Depend on pkg-config.

* debian/mandos.prerm (remove): Bug fix; check for
                                "/etc/init.d/mandos", not
                                "/etc/init.d/ssh".

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version='1.0' encoding='UTF-8'?>
 
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY VERSION "1.0">
5
5
<!ENTITY COMMANDNAME "mandos-keygen">
 
6
<!ENTITY TIMESTAMP "2008-09-20">
6
7
]>
7
8
 
8
9
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
9
10
  <refentryinfo>
10
 
    <title>&COMMANDNAME;</title>
11
 
    <!-- NWalsh's docbook scripts use this to generate the footer: -->
12
 
    <productname>&COMMANDNAME;</productname>
 
11
    <title>Mandos Manual</title>
 
12
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
 
13
    <productname>Mandos</productname>
13
14
    <productnumber>&VERSION;</productnumber>
 
15
    <date>&TIMESTAMP;</date>
14
16
    <authorgroup>
15
17
      <author>
16
18
        <firstname>Björn</firstname>
29
31
    </authorgroup>
30
32
    <copyright>
31
33
      <year>2008</year>
32
 
      <holder>Teddy Hogeborn &amp; Björn Påhlsson</holder>
 
34
      <holder>Teddy Hogeborn</holder>
 
35
      <holder>Björn Påhlsson</holder>
33
36
    </copyright>
34
 
    <legalnotice>
35
 
      <para>
36
 
        This manual page is free software: you can redistribute it
37
 
        and/or modify it under the terms of the GNU General Public
38
 
        License as published by the Free Software Foundation,
39
 
        either version 3 of the License, or (at your option) any
40
 
        later version.
41
 
      </para>
42
 
 
43
 
      <para>
44
 
        This manual page is distributed in the hope that it will
45
 
        be useful, but WITHOUT ANY WARRANTY; without even the
46
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
47
 
        PARTICULAR PURPOSE.  See the GNU General Public License
48
 
        for more details.
49
 
      </para>
50
 
 
51
 
      <para>
52
 
        You should have received a copy of the GNU General Public
53
 
        License along with this program; If not, see
54
 
        <ulink url="http://www.gnu.org/licenses/"/>.
55
 
      </para>
56
 
    </legalnotice>
 
37
    <xi:include href="legalnotice.xml"/>
57
38
  </refentryinfo>
58
 
 
 
39
  
59
40
  <refmeta>
60
41
    <refentrytitle>&COMMANDNAME;</refentrytitle>
61
42
    <manvolnum>8</manvolnum>
64
45
  <refnamediv>
65
46
    <refname><command>&COMMANDNAME;</command></refname>
66
47
    <refpurpose>
67
 
      Generate keys for <citerefentry><refentrytitle>password-request
68
 
      </refentrytitle><manvolnum>8mandos</manvolnum></citerefentry>
 
48
      Generate key and password for Mandos client and server.
69
49
    </refpurpose>
70
50
  </refnamediv>
71
 
 
 
51
  
72
52
  <refsynopsisdiv>
73
53
    <cmdsynopsis>
74
54
      <command>&COMMANDNAME;</command>
75
 
      <group choice="opt">
76
 
        <arg choice="plain"><option>--dir</option>
77
 
        <replaceable>directory</replaceable></arg>
78
 
      </group>
79
 
      <group choice="opt">
80
 
        <arg choice="plain"><option>--type</option>
81
 
        <replaceable>type</replaceable></arg>
82
 
      </group>
83
 
      <group choice="opt">
84
 
        <arg choice="plain"><option>--length</option>
85
 
        <replaceable>bits</replaceable></arg>
86
 
      </group>
87
 
      <group choice="opt">
88
 
        <arg choice="plain"><option>--name</option>
89
 
        <replaceable>NAME</replaceable></arg>
90
 
      </group>
91
 
      <group choice="opt">
92
 
        <arg choice="plain"><option>--email</option>
93
 
        <replaceable>EMAIL</replaceable></arg>
94
 
      </group>
95
 
      <group choice="opt">
96
 
        <arg choice="plain"><option>--comment</option>
97
 
        <replaceable>COMMENT</replaceable></arg>
98
 
      </group>
99
 
      <group choice="opt">
100
 
        <arg choice="plain"><option>--expire</option>
101
 
        <replaceable>TIME</replaceable></arg>
102
 
      </group>
103
 
      <group choice="opt">
104
 
        <arg choice="plain"><option>--force</option></arg>
105
 
      </group>
106
 
    </cmdsynopsis>
107
 
    <cmdsynopsis>
108
 
      <command>&COMMANDNAME;</command>
109
 
      <group choice="opt">
110
 
        <arg choice="plain"><option>-d</option>
111
 
        <replaceable>directory</replaceable></arg>
112
 
      </group>
113
 
      <group choice="opt">
114
 
        <arg choice="plain"><option>-t</option>
115
 
        <replaceable>type</replaceable></arg>
116
 
      </group>
117
 
      <group choice="opt">
118
 
        <arg choice="plain"><option>-l</option>
119
 
        <replaceable>bits</replaceable></arg>
120
 
      </group>
121
 
      <group choice="opt">
122
 
        <arg choice="plain"><option>-n</option>
123
 
        <replaceable>NAME</replaceable></arg>
124
 
      </group>
125
 
      <group choice="opt">
126
 
        <arg choice="plain"><option>-e</option>
127
 
        <replaceable>EMAIL</replaceable></arg>
128
 
      </group>
129
 
      <group choice="opt">
130
 
        <arg choice="plain"><option>-c</option>
131
 
        <replaceable>COMMENT</replaceable></arg>
132
 
      </group>
133
 
      <group choice="opt">
134
 
        <arg choice="plain"><option>-x</option>
135
 
        <replaceable>TIME</replaceable></arg>
136
 
      </group>
137
 
      <group choice="opt">
138
 
        <arg choice="plain"><option>-f</option></arg>
139
 
      </group>
140
 
    </cmdsynopsis>
141
 
    <cmdsynopsis>
142
 
      <command>&COMMANDNAME;</command>
143
 
      <group choice="req">
144
 
        <arg choice='plain'><option>-h</option></arg>
145
 
        <arg choice='plain'><option>--help</option></arg>
146
 
      </group>
147
 
    </cmdsynopsis>
148
 
    <cmdsynopsis>
149
 
      <command>&COMMANDNAME;</command>
150
 
      <group choice="req">
151
 
        <arg choice='plain'><option>-v</option></arg>
152
 
        <arg choice='plain'><option>--version</option></arg>
 
55
      <group>
 
56
        <arg choice="plain"><option>--dir
 
57
        <replaceable>DIRECTORY</replaceable></option></arg>
 
58
        <arg choice="plain"><option>-d
 
59
        <replaceable>DIRECTORY</replaceable></option></arg>
 
60
      </group>
 
61
      <sbr/>
 
62
      <group>
 
63
        <arg choice="plain"><option>--type
 
64
        <replaceable>KEYTYPE</replaceable></option></arg>
 
65
        <arg choice="plain"><option>-t
 
66
        <replaceable>KEYTYPE</replaceable></option></arg>
 
67
      </group>
 
68
      <sbr/>
 
69
      <group>
 
70
        <arg choice="plain"><option>--length
 
71
        <replaceable>BITS</replaceable></option></arg>
 
72
        <arg choice="plain"><option>-l
 
73
        <replaceable>BITS</replaceable></option></arg>
 
74
      </group>
 
75
      <sbr/>
 
76
      <group>
 
77
        <arg choice="plain"><option>--subtype
 
78
        <replaceable>KEYTYPE</replaceable></option></arg>
 
79
        <arg choice="plain"><option>-s
 
80
        <replaceable>KEYTYPE</replaceable></option></arg>
 
81
      </group>
 
82
      <sbr/>
 
83
      <group>
 
84
        <arg choice="plain"><option>--sublength
 
85
        <replaceable>BITS</replaceable></option></arg>
 
86
        <arg choice="plain"><option>-L
 
87
        <replaceable>BITS</replaceable></option></arg>
 
88
      </group>
 
89
      <sbr/>
 
90
      <group>
 
91
        <arg choice="plain"><option>--name
 
92
        <replaceable>NAME</replaceable></option></arg>
 
93
        <arg choice="plain"><option>-n
 
94
        <replaceable>NAME</replaceable></option></arg>
 
95
      </group>
 
96
      <sbr/>
 
97
      <group>
 
98
        <arg choice="plain"><option>--email
 
99
        <replaceable>ADDRESS</replaceable></option></arg>
 
100
        <arg choice="plain"><option>-e
 
101
        <replaceable>ADDRESS</replaceable></option></arg>
 
102
      </group>
 
103
      <sbr/>
 
104
      <group>
 
105
        <arg choice="plain"><option>--comment
 
106
        <replaceable>TEXT</replaceable></option></arg>
 
107
        <arg choice="plain"><option>-c
 
108
        <replaceable>TEXT</replaceable></option></arg>
 
109
      </group>
 
110
      <sbr/>
 
111
      <group>
 
112
        <arg choice="plain"><option>--expire
 
113
        <replaceable>TIME</replaceable></option></arg>
 
114
        <arg choice="plain"><option>-x
 
115
        <replaceable>TIME</replaceable></option></arg>
 
116
      </group>
 
117
      <sbr/>
 
118
      <arg><option>--force</option></arg>
 
119
    </cmdsynopsis>
 
120
    <cmdsynopsis>
 
121
      <command>&COMMANDNAME;</command>
 
122
      <group choice="req">
 
123
        <arg choice="plain"><option>--password</option></arg>
 
124
        <arg choice="plain"><option>-p</option></arg>
 
125
        <arg choice="plain"><option>--passfile
 
126
        <replaceable>FILE</replaceable></option></arg>
 
127
        <arg choice="plain"><option>-F</option>
 
128
        <replaceable>FILE</replaceable></arg>
 
129
      </group>
 
130
      <sbr/>
 
131
      <group>
 
132
        <arg choice="plain"><option>--dir
 
133
        <replaceable>DIRECTORY</replaceable></option></arg>
 
134
        <arg choice="plain"><option>-d
 
135
        <replaceable>DIRECTORY</replaceable></option></arg>
 
136
      </group>
 
137
      <sbr/>
 
138
      <group>
 
139
        <arg choice="plain"><option>--name
 
140
        <replaceable>NAME</replaceable></option></arg>
 
141
        <arg choice="plain"><option>-n
 
142
        <replaceable>NAME</replaceable></option></arg>
 
143
      </group>
 
144
    </cmdsynopsis>
 
145
    <cmdsynopsis>
 
146
      <command>&COMMANDNAME;</command>
 
147
      <group choice="req">
 
148
        <arg choice="plain"><option>--help</option></arg>
 
149
        <arg choice="plain"><option>-h</option></arg>
 
150
      </group>
 
151
    </cmdsynopsis>
 
152
    <cmdsynopsis>
 
153
      <command>&COMMANDNAME;</command>
 
154
      <group choice="req">
 
155
        <arg choice="plain"><option>--version</option></arg>
 
156
        <arg choice="plain"><option>-v</option></arg>
153
157
      </group>
154
158
    </cmdsynopsis>
155
159
  </refsynopsisdiv>
156
 
 
 
160
  
157
161
  <refsect1 id="description">
158
162
    <title>DESCRIPTION</title>
159
163
    <para>
160
164
      <command>&COMMANDNAME;</command> is a program to generate the
161
 
      OpenPGP keys used by
162
 
      <citerefentry><refentrytitle>password-request</refentrytitle>
163
 
      <manvolnum>8mandos</manvolnum></citerefentry>.  The keys are
 
165
      OpenPGP key used by
 
166
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
 
167
      <manvolnum>8mandos</manvolnum></citerefentry>.  The key is
164
168
      normally written to /etc/mandos for later installation into the
165
 
      initrd image, but this, like most things, can be changed with
166
 
      command line options.
 
169
      initrd image, but this, and most other things, can be changed
 
170
      with command line options.
 
171
    </para>
 
172
    <para>
 
173
      This program can also be used with the
 
174
      <option>--password</option> or <option>--passfile</option>
 
175
      options to generate a ready-made section for
 
176
      <filename>clients.conf</filename> (see
 
177
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
 
178
      <manvolnum>5</manvolnum></citerefentry>).
167
179
    </para>
168
180
  </refsect1>
169
181
  
170
182
  <refsect1 id="purpose">
171
183
    <title>PURPOSE</title>
172
 
 
173
184
    <para>
174
185
      The purpose of this is to enable <emphasis>remote and unattended
175
186
      rebooting</emphasis> of client host computer with an
176
187
      <emphasis>encrypted root file system</emphasis>.  See <xref
177
188
      linkend="overview"/> for details.
178
189
    </para>
179
 
 
180
190
  </refsect1>
181
191
  
182
192
  <refsect1 id="options">
183
193
    <title>OPTIONS</title>
184
 
 
 
194
    
185
195
    <variablelist>
186
196
      <varlistentry>
187
 
        <term><literal>-h</literal>, <literal>--help</literal></term>
 
197
        <term><option>--help</option></term>
 
198
        <term><option>-h</option></term>
188
199
        <listitem>
189
200
          <para>
190
201
            Show a help message and exit
191
202
          </para>
192
203
        </listitem>
193
204
      </varlistentry>
194
 
 
195
 
      <varlistentry>
196
 
        <term><literal>-d</literal>, <literal>--dir
197
 
        <replaceable>directory</replaceable></literal></term>
198
 
        <listitem>
199
 
          <para>
200
 
            Target directory for key files.
201
 
          </para>
202
 
        </listitem>
203
 
      </varlistentry>
204
 
 
205
 
      <varlistentry>
206
 
        <term><literal>-t</literal>, <literal>--type
207
 
        <replaceable>type</replaceable></literal></term>
208
 
        <listitem>
209
 
          <para>
210
 
            Key type.  Default is DSA.
211
 
          </para>
212
 
        </listitem>
213
 
      </varlistentry>
214
 
 
215
 
      <varlistentry>
216
 
        <term><literal>-l</literal>, <literal>--length
217
 
        <replaceable>bits</replaceable></literal></term>
218
 
        <listitem>
219
 
          <para>
220
 
            Key length in bits.  Default is 1024.
221
 
          </para>
222
 
        </listitem>
223
 
      </varlistentry>
224
 
 
225
 
      <varlistentry>
226
 
        <term><literal>-e</literal>, <literal>--email</literal>
227
 
        <replaceable>address</replaceable></term>
 
205
      
 
206
      <varlistentry>
 
207
        <term><option>--dir
 
208
        <replaceable>DIRECTORY</replaceable></option></term>
 
209
        <term><option>-d
 
210
        <replaceable>DIRECTORY</replaceable></option></term>
 
211
        <listitem>
 
212
          <para>
 
213
            Target directory for key files.  Default is
 
214
            <filename>/etc/mandos</filename>.
 
215
          </para>
 
216
        </listitem>
 
217
      </varlistentry>
 
218
      
 
219
      <varlistentry>
 
220
        <term><option>--type
 
221
        <replaceable>TYPE</replaceable></option></term>
 
222
        <term><option>-t
 
223
        <replaceable>TYPE</replaceable></option></term>
 
224
        <listitem>
 
225
          <para>
 
226
            Key type.  Default is <quote>DSA</quote>.
 
227
          </para>
 
228
        </listitem>
 
229
      </varlistentry>
 
230
      
 
231
      <varlistentry>
 
232
        <term><option>--length
 
233
        <replaceable>BITS</replaceable></option></term>
 
234
        <term><option>-l
 
235
        <replaceable>BITS</replaceable></option></term>
 
236
        <listitem>
 
237
          <para>
 
238
            Key length in bits.  Default is 2048.
 
239
          </para>
 
240
        </listitem>
 
241
      </varlistentry>
 
242
      
 
243
      <varlistentry>
 
244
        <term><option>--subtype
 
245
        <replaceable>KEYTYPE</replaceable></option></term>
 
246
        <term><option>-s
 
247
        <replaceable>KEYTYPE</replaceable></option></term>
 
248
        <listitem>
 
249
          <para>
 
250
            Subkey type.  Default is <quote>ELG-E</quote> (Elgamal
 
251
            encryption-only).
 
252
          </para>
 
253
        </listitem>
 
254
      </varlistentry>
 
255
      
 
256
      <varlistentry>
 
257
        <term><option>--sublength
 
258
        <replaceable>BITS</replaceable></option></term>
 
259
        <term><option>-L
 
260
        <replaceable>BITS</replaceable></option></term>
 
261
        <listitem>
 
262
          <para>
 
263
            Subkey length in bits.  Default is 2048.
 
264
          </para>
 
265
        </listitem>
 
266
      </varlistentry>
 
267
      
 
268
      <varlistentry>
 
269
        <term><option>--email
 
270
        <replaceable>ADDRESS</replaceable></option></term>
 
271
        <term><option>-e
 
272
        <replaceable>ADDRESS</replaceable></option></term>
228
273
        <listitem>
229
274
          <para>
230
275
            Email address of key.  Default is empty.
231
276
          </para>
232
277
        </listitem>
233
278
      </varlistentry>
234
 
 
 
279
      
235
280
      <varlistentry>
236
 
        <term><literal>-c</literal>, <literal>--comment</literal>
237
 
        <replaceable>comment</replaceable></term>
 
281
        <term><option>--comment
 
282
        <replaceable>TEXT</replaceable></option></term>
 
283
        <term><option>-c
 
284
        <replaceable>TEXT</replaceable></option></term>
238
285
        <listitem>
239
286
          <para>
240
287
            Comment field for key.  The default value is
241
 
            "<literal>Mandos client key</literal>".
 
288
            <quote><literal>Mandos client key</literal></quote>.
242
289
          </para>
243
290
        </listitem>
244
291
      </varlistentry>
245
 
 
 
292
      
246
293
      <varlistentry>
247
 
        <term><literal>-x</literal>, <literal>--expire</literal>
248
 
        <replaceable>time</replaceable></term>
 
294
        <term><option>--expire
 
295
        <replaceable>TIME</replaceable></option></term>
 
296
        <term><option>-x
 
297
        <replaceable>TIME</replaceable></option></term>
249
298
        <listitem>
250
299
          <para>
251
300
            Key expire time.  Default is no expiration.  See
254
303
          </para>
255
304
        </listitem>
256
305
      </varlistentry>
257
 
 
258
 
      <varlistentry>
259
 
        <term><literal>-f</literal>, <literal>--force</literal></term>
260
 
        <listitem>
261
 
          <para>
262
 
            Force overwriting old keys.
 
306
      
 
307
      <varlistentry>
 
308
        <term><option>--force</option></term>
 
309
        <term><option>-f</option></term>
 
310
        <listitem>
 
311
          <para>
 
312
            Force overwriting old key.
 
313
          </para>
 
314
        </listitem>
 
315
      </varlistentry>
 
316
      <varlistentry>
 
317
        <term><option>--password</option></term>
 
318
        <term><option>-p</option></term>
 
319
        <listitem>
 
320
          <para>
 
321
            Prompt for a password and encrypt it with the key already
 
322
            present in either <filename>/etc/mandos</filename> or the
 
323
            directory specified with the <option>--dir</option>
 
324
            option.  Outputs, on standard output, a section suitable
 
325
            for inclusion in <citerefentry><refentrytitle
 
326
            >mandos-clients.conf</refentrytitle><manvolnum
 
327
            >8</manvolnum></citerefentry>.  The host name or the name
 
328
            specified with the <option>--name</option> option is used
 
329
            for the section header.  All other options are ignored,
 
330
            and no key is created.
 
331
          </para>
 
332
        </listitem>
 
333
      </varlistentry>
 
334
      <varlistentry>
 
335
        <term><option>--passfile
 
336
        <replaceable>FILE</replaceable></option></term>
 
337
        <term><option>-F
 
338
        <replaceable>FILE</replaceable></option></term>
 
339
        <listitem>
 
340
          <para>
 
341
            The same as <option>--password</option>, but read from
 
342
            <replaceable>FILE</replaceable>, not the terminal.
263
343
          </para>
264
344
        </listitem>
265
345
      </varlistentry>
266
346
    </variablelist>
267
347
  </refsect1>
268
 
 
 
348
  
269
349
  <refsect1 id="overview">
270
350
    <title>OVERVIEW</title>
271
351
    <xi:include href="overview.xml"/>
272
352
    <para>
273
 
      This program is a small program to generate new OpenPGP keys for
274
 
      new Mandos clients.
 
353
      This program is a small utility to generate new OpenPGP keys for
 
354
      new Mandos clients, and to generate sections for inclusion in
 
355
      <filename>clients.conf</filename> on the server.
275
356
    </para>
276
357
  </refsect1>
277
 
 
 
358
  
278
359
  <refsect1 id="exit_status">
279
360
    <title>EXIT STATUS</title>
280
361
    <para>
281
 
      The exit status will be 0 if new keys were successfully created,
282
 
      otherwise not.
 
362
      The exit status will be 0 if a new key (or password, if the
 
363
      <option>--password</option> option was used) was successfully
 
364
      created, otherwise not.
283
365
    </para>
284
366
  </refsect1>
285
367
  
287
369
    <title>ENVIRONMENT</title>
288
370
    <variablelist>
289
371
      <varlistentry>
290
 
        <term><varname>TMPDIR</varname></term>
 
372
        <term><envar>TMPDIR</envar></term>
291
373
        <listitem>
292
374
          <para>
293
375
            If set, temporary files will be created here. See
336
418
      </varlistentry>
337
419
    </variablelist>
338
420
  </refsect1>
339
 
 
340
 
  <refsect1 id="bugs">
341
 
    <title>BUGS</title>
342
 
    <para>
343
 
      None are known at this time.
344
 
    </para>
345
 
  </refsect1>
346
 
 
 
421
  
 
422
<!--   <refsect1 id="bugs"> -->
 
423
<!--     <title>BUGS</title> -->
 
424
<!--     <para> -->
 
425
<!--     </para> -->
 
426
<!--   </refsect1> -->
 
427
  
347
428
  <refsect1 id="example">
348
429
    <title>EXAMPLE</title>
349
430
    <informalexample>
351
432
        Normal invocation needs no options:
352
433
      </para>
353
434
      <para>
354
 
        <userinput>mandos-keygen</userinput>
 
435
        <userinput>&COMMANDNAME;</userinput>
355
436
      </para>
356
437
    </informalexample>
357
438
    <informalexample>
358
439
      <para>
359
 
        Create keys in another directory and of another type.  Force
 
440
        Create key in another directory and of another type.  Force
360
441
        overwriting old key files:
361
442
      </para>
362
443
      <para>
363
444
 
364
445
<!-- do not wrap this line -->
365
 
<userinput>mandos-keygen --dir ~/keydir --type RSA --force</userinput>
 
446
<userinput>&COMMANDNAME; --dir ~/keydir --type RSA --force</userinput>
 
447
 
 
448
      </para>
 
449
    </informalexample>
 
450
    <informalexample>
 
451
      <para>
 
452
        Prompt for a password, encrypt it with the key in
 
453
        <filename>/etc/mandos</filename> and output a section suitable
 
454
        for <filename>clients.conf</filename>.
 
455
      </para>
 
456
      <para>
 
457
        <userinput>&COMMANDNAME; --password</userinput>
 
458
      </para>
 
459
    </informalexample>
 
460
    <informalexample>
 
461
      <para>
 
462
        Prompt for a password, encrypt it with the key in the
 
463
        <filename>client-key</filename> directory and output a section
 
464
        suitable for <filename>clients.conf</filename>.
 
465
      </para>
 
466
      <para>
 
467
 
 
468
<!-- do not wrap this line -->
 
469
<userinput>&COMMANDNAME; --password --dir client-key</userinput>
366
470
 
367
471
      </para>
368
472
    </informalexample>
369
473
  </refsect1>
370
 
 
 
474
  
371
475
  <refsect1 id="security">
372
476
    <title>SECURITY</title>
373
477
    <para>
374
 
      The <option>--type</option> and <option>--length</option>
375
 
      options can be used to create keys of insufficient security.  If
376
 
      in doubt, leave them to the default values.
 
478
      The <option>--type</option>, <option>--length</option>,
 
479
      <option>--subtype</option>, and <option>--sublength</option>
 
480
      options can be used to create keys of low security.  If in
 
481
      doubt, leave them to the default values.
377
482
    </para>
378
483
    <para>
379
 
      The key expire time is not guaranteed to be honored by
380
 
      <citerefentry><refentrytitle>mandos</refentrytitle>
 
484
      The key expire time is <emphasis>not</emphasis> guaranteed to be
 
485
      honored by <citerefentry><refentrytitle>mandos</refentrytitle>
381
486
      <manvolnum>8</manvolnum></citerefentry>.
382
487
    </para>
383
488
  </refsect1>
384
 
 
 
489
  
385
490
  <refsect1 id="see_also">
386
491
    <title>SEE ALSO</title>
387
492
    <para>
388
 
      <citerefentry><refentrytitle>password-request</refentrytitle>
389
 
      <manvolnum>8mandos</manvolnum></citerefentry>,
390
 
      <citerefentry><refentrytitle>mandos</refentrytitle>
391
 
      <manvolnum>8</manvolnum></citerefentry>, and
392
493
      <citerefentry><refentrytitle>gpg</refentrytitle>
393
 
      <manvolnum>1</manvolnum></citerefentry>
 
494
      <manvolnum>1</manvolnum></citerefentry>,
 
495
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
 
496
      <manvolnum>5</manvolnum></citerefentry>,
 
497
      <citerefentry><refentrytitle>mandos</refentrytitle>
 
498
      <manvolnum>8</manvolnum></citerefentry>,
 
499
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
 
500
      <manvolnum>8mandos</manvolnum></citerefentry>
394
501
    </para>
395
502
  </refsect1>
396
503
  
397
504
</refentry>
 
505
<!-- Local Variables: -->
 
506
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
 
507
<!-- time-stamp-end: "[\"']>" -->
 
508
<!-- time-stamp-format: "%:y-%02m-%02d" -->
 
509
<!-- End: -->