1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
<!ENTITY VERSION "1.0">
4
5
<!ENTITY COMMANDNAME "mandos-keygen">
5
<!ENTITY TIMESTAMP "2015-07-20">
6
<!ENTITY % common SYSTEM "common.ent">
6
<!ENTITY TIMESTAMP "2008-08-31">
10
9
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
11
<title>Mandos Manual</title>
13
12
<!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
13
<productname>Mandos</productname>
15
<productnumber>&version;</productnumber>
14
<productnumber>&VERSION;</productnumber>
16
15
<date>&TIMESTAMP;</date>
19
18
<firstname>Björn</firstname>
20
19
<surname>Påhlsson</surname>
22
<email>belorn@recompile.se</email>
21
<email>belorn@fukt.bsnet.se</email>
26
25
<firstname>Teddy</firstname>
27
26
<surname>Hogeborn</surname>
29
<email>teddy@recompile.se</email>
28
<email>teddy@fukt.bsnet.se</email>
42
34
<holder>Teddy Hogeborn</holder>
43
35
<holder>Björn Påhlsson</holder>
45
<xi:include href="legalnotice.xml"/>
39
This manual page is free software: you can redistribute it
40
and/or modify it under the terms of the GNU General Public
41
License as published by the Free Software Foundation,
42
either version 3 of the License, or (at your option) any
47
This manual page is distributed in the hope that it will
48
be useful, but WITHOUT ANY WARRANTY; without even the
49
implied warranty of MERCHANTABILITY or FITNESS FOR A
50
PARTICULAR PURPOSE. See the GNU General Public License
55
You should have received a copy of the GNU General Public
56
License along with this program; If not, see
57
<ulink url="http://www.gnu.org/licenses/"/>.
49
63
<refentrytitle>&COMMANDNAME;</refentrytitle>
50
64
<manvolnum>8</manvolnum>
123
137
<replaceable>TIME</replaceable></option></arg>
127
<arg choice="plain"><option>--force</option></arg>
128
<arg choice="plain"><option>-f</option></arg>
140
<arg><option>--force</option></arg>
132
143
<command>&COMMANDNAME;</command>
133
144
<group choice="req">
134
145
<arg choice="plain"><option>--password</option></arg>
135
146
<arg choice="plain"><option>-p</option></arg>
136
<arg choice="plain"><option>--passfile
137
<replaceable>FILE</replaceable></option></arg>
138
<arg choice="plain"><option>-F</option>
139
<replaceable>FILE</replaceable></arg>
152
159
<arg choice="plain"><option>-n
153
160
<replaceable>NAME</replaceable></option></arg>
156
<arg choice="plain"><option>--no-ssh</option></arg>
157
<arg choice="plain"><option>-S</option></arg>
161
164
<command>&COMMANDNAME;</command>
179
182
<command>&COMMANDNAME;</command> is a program to generate the
180
183
OpenPGP key used by
181
<citerefentry><refentrytitle>mandos-client</refentrytitle>
184
<citerefentry><refentrytitle>password-request</refentrytitle>
182
185
<manvolnum>8mandos</manvolnum></citerefentry>. The key is
183
186
normally written to /etc/mandos for later installation into the
184
187
initrd image, but this, and most other things, can be changed
188
191
This program can also be used with the
189
<option>--password</option> or <option>--passfile</option>
190
options to generate a ready-made section for
191
<filename>clients.conf</filename> (see
192
<option>--password</option> option to generate a ready-made
193
section for <filename>clients.conf</filename> (see
192
194
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
193
195
<manvolnum>5</manvolnum></citerefentry>).
262
264
<replaceable>KEYTYPE</replaceable></option></term>
265
Subkey type. Default is <quote>RSA</quote> (Elgamal
267
Subkey type. Default is <quote>ELG-E</quote> (Elgamal
266
268
encryption-only).
272
274
<term><option>--sublength
273
275
<replaceable>BITS</replaceable></option></term>
299
301
<replaceable>TEXT</replaceable></option></term>
302
Comment field for key. Default is empty.
304
Comment field for key. The default value is
305
<quote><literal>Mandos client key</literal></quote>.
308
311
<term><option>--expire
309
312
<replaceable>TIME</replaceable></option></term>
349
<term><option>--passfile
350
<replaceable>FILE</replaceable></option></term>
352
<replaceable>FILE</replaceable></option></term>
355
The same as <option>--password</option>, but read from
356
<replaceable>FILE</replaceable>, not the terminal.
361
<term><option>--no-ssh</option></term>
362
<term><option>-S</option></term>
365
When <option>--password</option> or
366
<option>--passfile</option> is given, this option will
367
prevent <command>&COMMANDNAME;</command> from calling
368
<command>ssh-keyscan</command> to get an SSH fingerprint
369
for this host and, if successful, output suitable config
370
options to use this fingerprint as a
371
<option>checker</option> option in the output. This is
372
otherwise the default behavior.
379
354
<refsect1 id="overview">
380
355
<title>OVERVIEW</title>
381
356
<xi:include href="overview.xml"/>
479
455
</informalexample>
480
456
<informalexample>
482
Prompt for a password, encrypt it with the key in <filename
483
class="directory">/etc/mandos</filename> and output a section
484
suitable for <filename>clients.conf</filename>.
458
Prompt for a password, encrypt it with the key in
459
<filename>/etc/mandos</filename> and output a section suitable
460
for <filename>clients.conf</filename>.
487
463
<userinput>&COMMANDNAME; --password</userinput>
516
492
<manvolnum>8</manvolnum></citerefentry>.
520
496
<refsect1 id="see_also">
521
497
<title>SEE ALSO</title>
523
<citerefentry><refentrytitle>intro</refentrytitle>
524
<manvolnum>8mandos</manvolnum></citerefentry>,
525
499
<citerefentry><refentrytitle>gpg</refentrytitle>
526
500
<manvolnum>1</manvolnum></citerefentry>,
527
501
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
528
502
<manvolnum>5</manvolnum></citerefentry>,
529
503
<citerefentry><refentrytitle>mandos</refentrytitle>
530
504
<manvolnum>8</manvolnum></citerefentry>,
531
<citerefentry><refentrytitle>mandos-client</refentrytitle>
532
<manvolnum>8mandos</manvolnum></citerefentry>,
533
<citerefentry><refentrytitle>ssh-keyscan</refentrytitle>
534
<manvolnum>1</manvolnum></citerefentry>
505
<citerefentry><refentrytitle>password-request</refentrytitle>
506
<manvolnum>8mandos</manvolnum></citerefentry>