46
66
<refname><command>&COMMANDNAME;</command></refname>
48
Generate key and password for Mandos client and server.
68
Generate keys for <citerefentry><refentrytitle>password-request
69
</refentrytitle><manvolnum>8mandos</manvolnum></citerefentry>
54
75
<command>&COMMANDNAME;</command>
56
<arg choice="plain"><option>--dir
57
<replaceable>DIRECTORY</replaceable></option></arg>
58
<arg choice="plain"><option>-d
59
<replaceable>DIRECTORY</replaceable></option></arg>
63
<arg choice="plain"><option>--type
64
<replaceable>KEYTYPE</replaceable></option></arg>
65
<arg choice="plain"><option>-t
66
<replaceable>KEYTYPE</replaceable></option></arg>
70
<arg choice="plain"><option>--length
71
<replaceable>BITS</replaceable></option></arg>
72
<arg choice="plain"><option>-l
73
<replaceable>BITS</replaceable></option></arg>
77
<arg choice="plain"><option>--subtype
78
<replaceable>KEYTYPE</replaceable></option></arg>
79
<arg choice="plain"><option>-s
80
<replaceable>KEYTYPE</replaceable></option></arg>
84
<arg choice="plain"><option>--sublength
85
<replaceable>BITS</replaceable></option></arg>
86
<arg choice="plain"><option>-L
87
<replaceable>BITS</replaceable></option></arg>
91
<arg choice="plain"><option>--name
92
<replaceable>NAME</replaceable></option></arg>
93
<arg choice="plain"><option>-n
94
<replaceable>NAME</replaceable></option></arg>
98
<arg choice="plain"><option>--email
99
<replaceable>ADDRESS</replaceable></option></arg>
100
<arg choice="plain"><option>-e
101
<replaceable>ADDRESS</replaceable></option></arg>
105
<arg choice="plain"><option>--comment
106
<replaceable>TEXT</replaceable></option></arg>
107
<arg choice="plain"><option>-c
108
<replaceable>TEXT</replaceable></option></arg>
112
<arg choice="plain"><option>--expire
113
<replaceable>TIME</replaceable></option></arg>
114
<arg choice="plain"><option>-x
115
<replaceable>TIME</replaceable></option></arg>
118
<arg><option>--force</option></arg>
121
<command>&COMMANDNAME;</command>
123
<arg choice="plain"><option>--password</option></arg>
124
<arg choice="plain"><option>-p</option></arg>
128
<arg choice="plain"><option>--dir
129
<replaceable>DIRECTORY</replaceable></option></arg>
130
<arg choice="plain"><option>-d
131
<replaceable>DIRECTORY</replaceable></option></arg>
135
<arg choice="plain"><option>--name
136
<replaceable>NAME</replaceable></option></arg>
137
<arg choice="plain"><option>-n
138
<replaceable>NAME</replaceable></option></arg>
142
<command>&COMMANDNAME;</command>
144
<arg choice="plain"><option>--help</option></arg>
145
<arg choice="plain"><option>-h</option></arg>
149
<command>&COMMANDNAME;</command>
151
<arg choice="plain"><option>--version</option></arg>
152
<arg choice="plain"><option>-v</option></arg>
77
<arg choice="plain"><option>--dir</option>
78
<replaceable>directory</replaceable></arg>
81
<arg choice="plain"><option>--type</option>
82
<replaceable>type</replaceable></arg>
85
<arg choice="plain"><option>--length</option>
86
<replaceable>bits</replaceable></arg>
89
<arg choice="plain"><option>--name</option>
90
<replaceable>NAME</replaceable></arg>
93
<arg choice="plain"><option>--email</option>
94
<replaceable>EMAIL</replaceable></arg>
97
<arg choice="plain"><option>--comment</option>
98
<replaceable>COMMENT</replaceable></arg>
101
<arg choice="plain"><option>--expire</option>
102
<replaceable>TIME</replaceable></arg>
105
<arg choice="plain"><option>--force</option></arg>
109
<command>&COMMANDNAME;</command>
111
<arg choice="plain"><option>-d</option>
112
<replaceable>directory</replaceable></arg>
115
<arg choice="plain"><option>-t</option>
116
<replaceable>type</replaceable></arg>
119
<arg choice="plain"><option>-l</option>
120
<replaceable>bits</replaceable></arg>
123
<arg choice="plain"><option>-n</option>
124
<replaceable>NAME</replaceable></arg>
127
<arg choice="plain"><option>-e</option>
128
<replaceable>EMAIL</replaceable></arg>
131
<arg choice="plain"><option>-c</option>
132
<replaceable>COMMENT</replaceable></arg>
135
<arg choice="plain"><option>-x</option>
136
<replaceable>TIME</replaceable></arg>
139
<arg choice="plain"><option>-f</option></arg>
143
<command>&COMMANDNAME;</command>
145
<arg choice='plain'><option>-h</option></arg>
146
<arg choice='plain'><option>--help</option></arg>
150
<command>&COMMANDNAME;</command>
152
<arg choice='plain'><option>-v</option></arg>
153
<arg choice='plain'><option>--version</option></arg>
155
156
</refsynopsisdiv>
157
158
<refsect1 id="description">
158
159
<title>DESCRIPTION</title>
160
161
<command>&COMMANDNAME;</command> is a program to generate the
162
<citerefentry><refentrytitle>mandos-client</refentrytitle>
163
<manvolnum>8mandos</manvolnum></citerefentry>. The key is
163
<citerefentry><refentrytitle>password-request</refentrytitle>
164
<manvolnum>8mandos</manvolnum></citerefentry>. The keys are
164
165
normally written to /etc/mandos for later installation into the
165
initrd image, but this, and most other things, can be changed
166
with command line options.
169
This program can also be used with the
170
<option>--password</option> option to generate a ready-made
171
section for <filename>clients.conf</filename> (see
172
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
173
<manvolnum>5</manvolnum></citerefentry>).
166
initrd image, but this, like most things, can be changed with
167
command line options.
177
171
<refsect1 id="purpose">
178
172
<title>PURPOSE</title>
180
175
The purpose of this is to enable <emphasis>remote and unattended
181
176
rebooting</emphasis> of client host computer with an
182
177
<emphasis>encrypted root file system</emphasis>. See <xref
183
178
linkend="overview"/> for details.
187
183
<refsect1 id="options">
188
184
<title>OPTIONS</title>
192
<term><option>--help</option></term>
193
<term><option>-h</option></term>
188
<term><literal>-h</literal>, <literal>--help</literal></term>
196
191
Show a help message and exit
203
<replaceable>DIRECTORY</replaceable></option></term>
205
<replaceable>DIRECTORY</replaceable></option></term>
208
Target directory for key files. Default is
209
<filename>/etc/mandos</filename>.
216
<replaceable>TYPE</replaceable></option></term>
218
<replaceable>TYPE</replaceable></option></term>
221
Key type. Default is <quote>DSA</quote>.
227
<term><option>--length
228
<replaceable>BITS</replaceable></option></term>
230
<replaceable>BITS</replaceable></option></term>
233
Key length in bits. Default is 2048.
239
<term><option>--subtype
240
<replaceable>KEYTYPE</replaceable></option></term>
242
<replaceable>KEYTYPE</replaceable></option></term>
245
Subkey type. Default is <quote>ELG-E</quote> (Elgamal
252
<term><option>--sublength
253
<replaceable>BITS</replaceable></option></term>
255
<replaceable>BITS</replaceable></option></term>
258
Subkey length in bits. Default is 2048.
264
<term><option>--email
265
<replaceable>ADDRESS</replaceable></option></term>
267
<replaceable>ADDRESS</replaceable></option></term>
197
<term><literal>-d</literal>, <literal>--dir
198
<replaceable>directory</replaceable></literal></term>
201
Target directory for key files.
207
<term><literal>-t</literal>, <literal>--type
208
<replaceable>type</replaceable></literal></term>
211
Key type. Default is DSA.
217
<term><literal>-l</literal>, <literal>--length
218
<replaceable>bits</replaceable></literal></term>
221
Key length in bits. Default is 1024.
227
<term><literal>-e</literal>, <literal>--email</literal>
228
<replaceable>address</replaceable></term>
270
231
Email address of key. Default is empty.
276
<term><option>--comment
277
<replaceable>TEXT</replaceable></option></term>
279
<replaceable>TEXT</replaceable></option></term>
237
<term><literal>-c</literal>, <literal>--comment</literal>
238
<replaceable>comment</replaceable></term>
282
241
Comment field for key. The default value is
283
<quote><literal>Mandos client key</literal></quote>.
242
"<literal>Mandos client key</literal>".
289
<term><option>--expire
290
<replaceable>TIME</replaceable></option></term>
292
<replaceable>TIME</replaceable></option></term>
248
<term><literal>-x</literal>, <literal>--expire</literal>
249
<replaceable>time</replaceable></term>
295
252
Key expire time. Default is no expiration. See
303
<term><option>--force</option></term>
304
<term><option>-f</option></term>
307
Force overwriting old key.
312
<term><option>--password</option></term>
313
<term><option>-p</option></term>
316
Prompt for a password and encrypt it with the key already
317
present in either <filename>/etc/mandos</filename> or the
318
directory specified with the <option>--dir</option>
319
option. Outputs, on standard output, a section suitable
320
for inclusion in <citerefentry><refentrytitle
321
>mandos-clients.conf</refentrytitle><manvolnum
322
>8</manvolnum></citerefentry>. The host name or the name
323
specified with the <option>--name</option> option is used
324
for the section header. All other options are ignored,
325
and no key is created.
260
<term><literal>-f</literal>, <literal>--force</literal></term>
263
Force overwriting old keys.
332
270
<refsect1 id="overview">
333
271
<title>OVERVIEW</title>
334
<xi:include href="overview.xml"/>
336
This program is a small utility to generate new OpenPGP keys for
337
new Mandos clients, and to generate sections for inclusion in
338
<filename>clients.conf</filename> on the server.
274
This program is a small program to generate new OpenPGP keys for
342
279
<refsect1 id="exit_status">
343
280
<title>EXIT STATUS</title>
345
The exit status will be 0 if a new key (or password, if the
346
<option>--password</option> option was used) was successfully
347
created, otherwise not.
351
<refsect1 id="environment">
352
<title>ENVIRONMENT</title>
355
<term><envar>TMPDIR</envar></term>
358
If set, temporary files will be created here. See
359
<citerefentry><refentrytitle>mktemp</refentrytitle>
360
<manvolnum>1</manvolnum></citerefentry>.
367
285
<refsect1 id="file">
368
286
<title>FILES</title>
370
Use the <option>--dir</option> option to change where
371
<command>&COMMANDNAME;</command> will write the key files. The
372
default file names are shown here.
376
<term><filename>/etc/mandos/seckey.txt</filename></term>
379
OpenPGP secret key file which will be created or
385
<term><filename>/etc/mandos/pubkey.txt</filename></term>
388
OpenPGP public key file which will be created or
394
<term><filename>/tmp</filename></term>
397
Temporary files will be written here if
398
<varname>TMPDIR</varname> is not set.
405
<!-- <refsect1 id="bugs"> -->
406
<!-- <title>BUGS</title> -->
411
297
<refsect1 id="example">
412
298
<title>EXAMPLE</title>
415
Normal invocation needs no options:
418
<userinput>&COMMANDNAME;</userinput>
423
Create key in another directory and of another type. Force
424
overwriting old key files:
428
<!-- do not wrap this line -->
429
<userinput>&COMMANDNAME; --dir ~/keydir --type RSA --force</userinput>
435
Prompt for a password, encrypt it with the key in
436
<filename>/etc/mandos</filename> and output a section suitable
437
for <filename>clients.conf</filename>.
440
<userinput>&COMMANDNAME; --password</userinput>
445
Prompt for a password, encrypt it with the key in the
446
<filename>client-key</filename> directory and output a section
447
suitable for <filename>clients.conf</filename>.
451
<!-- do not wrap this line -->
452
<userinput>&COMMANDNAME; --password --dir client-key</userinput>
458
303
<refsect1 id="security">
459
304
<title>SECURITY</title>
461
The <option>--type</option>, <option>--length</option>,
462
<option>--subtype</option>, and <option>--sublength</option>
463
options can be used to create keys of low security. If in
464
doubt, leave them to the default values.
467
The key expire time is <emphasis>not</emphasis> guaranteed to be
468
honored by <citerefentry><refentrytitle>mandos</refentrytitle>
469
<manvolnum>8</manvolnum></citerefentry>.
473
309
<refsect1 id="see_also">
474
310
<title>SEE ALSO</title>
312
<citerefentry><refentrytitle>password-request</refentrytitle>
313
<manvolnum>8mandos</manvolnum></citerefentry>,
314
<citerefentry><refentrytitle>mandos</refentrytitle>
315
<manvolnum>8</manvolnum></citerefentry>, and
476
316
<citerefentry><refentrytitle>gpg</refentrytitle>
477
<manvolnum>1</manvolnum></citerefentry>,
478
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
479
<manvolnum>5</manvolnum></citerefentry>,
480
<citerefentry><refentrytitle>mandos</refentrytitle>
481
<manvolnum>8</manvolnum></citerefentry>,
482
<citerefentry><refentrytitle>mandos-client</refentrytitle>
483
<manvolnum>8mandos</manvolnum></citerefentry>
317
<manvolnum>1</manvolnum></citerefentry>
488
<!-- Local Variables: -->
489
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
490
<!-- time-stamp-end: "[\"']>" -->
491
<!-- time-stamp-format: "%:y-%02m-%02d" -->