66
46
<refname><command>&COMMANDNAME;</command></refname>
68
Generate keys for <citerefentry><refentrytitle>password-request
69
</refentrytitle><manvolnum>8mandos</manvolnum></citerefentry>
48
Generate key and password for Mandos client and server.
75
54
<command>&COMMANDNAME;</command>
77
<arg choice="plain"><option>--dir</option>
78
<replaceable>directory</replaceable></arg>
81
<arg choice="plain"><option>--type</option>
82
<replaceable>type</replaceable></arg>
85
<arg choice="plain"><option>--length</option>
86
<replaceable>bits</replaceable></arg>
89
<arg choice="plain"><option>--subtype</option>
90
<replaceable>type</replaceable></arg>
93
<arg choice="plain"><option>--sublength</option>
94
<replaceable>bits</replaceable></arg>
97
<arg choice="plain"><option>--name</option>
98
<replaceable>NAME</replaceable></arg>
101
<arg choice="plain"><option>--email</option>
102
<replaceable>EMAIL</replaceable></arg>
105
<arg choice="plain"><option>--comment</option>
106
<replaceable>COMMENT</replaceable></arg>
109
<arg choice="plain"><option>--expire</option>
110
<replaceable>TIME</replaceable></arg>
113
<arg choice="plain"><option>--force</option></arg>
117
<command>&COMMANDNAME;</command>
119
<arg choice="plain"><option>-d</option>
120
<replaceable>directory</replaceable></arg>
123
<arg choice="plain"><option>-t</option>
124
<replaceable>type</replaceable></arg>
127
<arg choice="plain"><option>-l</option>
128
<replaceable>bits</replaceable></arg>
131
<arg choice="plain"><option>-s</option>
132
<replaceable>type</replaceable></arg>
135
<arg choice="plain"><option>-L</option>
136
<replaceable>bits</replaceable></arg>
139
<arg choice="plain"><option>-n</option>
140
<replaceable>NAME</replaceable></arg>
143
<arg choice="plain"><option>-e</option>
144
<replaceable>EMAIL</replaceable></arg>
147
<arg choice="plain"><option>-c</option>
148
<replaceable>COMMENT</replaceable></arg>
151
<arg choice="plain"><option>-x</option>
152
<replaceable>TIME</replaceable></arg>
155
<arg choice="plain"><option>-f</option></arg>
159
<command>&COMMANDNAME;</command>
56
<arg choice="plain"><option>--dir
57
<replaceable>DIRECTORY</replaceable></option></arg>
58
<arg choice="plain"><option>-d
59
<replaceable>DIRECTORY</replaceable></option></arg>
63
<arg choice="plain"><option>--type
64
<replaceable>KEYTYPE</replaceable></option></arg>
65
<arg choice="plain"><option>-t
66
<replaceable>KEYTYPE</replaceable></option></arg>
70
<arg choice="plain"><option>--length
71
<replaceable>BITS</replaceable></option></arg>
72
<arg choice="plain"><option>-l
73
<replaceable>BITS</replaceable></option></arg>
77
<arg choice="plain"><option>--subtype
78
<replaceable>KEYTYPE</replaceable></option></arg>
79
<arg choice="plain"><option>-s
80
<replaceable>KEYTYPE</replaceable></option></arg>
84
<arg choice="plain"><option>--sublength
85
<replaceable>BITS</replaceable></option></arg>
86
<arg choice="plain"><option>-L
87
<replaceable>BITS</replaceable></option></arg>
91
<arg choice="plain"><option>--name
92
<replaceable>NAME</replaceable></option></arg>
93
<arg choice="plain"><option>-n
94
<replaceable>NAME</replaceable></option></arg>
98
<arg choice="plain"><option>--email
99
<replaceable>ADDRESS</replaceable></option></arg>
100
<arg choice="plain"><option>-e
101
<replaceable>ADDRESS</replaceable></option></arg>
105
<arg choice="plain"><option>--comment
106
<replaceable>TEXT</replaceable></option></arg>
107
<arg choice="plain"><option>-c
108
<replaceable>TEXT</replaceable></option></arg>
112
<arg choice="plain"><option>--expire
113
<replaceable>TIME</replaceable></option></arg>
114
<arg choice="plain"><option>-x
115
<replaceable>TIME</replaceable></option></arg>
118
<arg><option>--force</option></arg>
121
<command>&COMMANDNAME;</command>
123
<arg choice="plain"><option>--password</option></arg>
124
<arg choice="plain"><option>-p</option></arg>
128
<arg choice="plain"><option>--dir
129
<replaceable>DIRECTORY</replaceable></option></arg>
130
<arg choice="plain"><option>-d
131
<replaceable>DIRECTORY</replaceable></option></arg>
135
<arg choice="plain"><option>--name
136
<replaceable>NAME</replaceable></option></arg>
137
<arg choice="plain"><option>-n
138
<replaceable>NAME</replaceable></option></arg>
142
<command>&COMMANDNAME;</command>
144
<arg choice="plain"><option>--help</option></arg>
161
145
<arg choice="plain"><option>-h</option></arg>
162
<arg choice="plain"><option>--help</option></arg>
166
149
<command>&COMMANDNAME;</command>
167
150
<group choice="req">
151
<arg choice="plain"><option>--version</option></arg>
168
152
<arg choice="plain"><option>-v</option></arg>
169
<arg choice="plain"><option>--version</option></arg>
172
155
</refsynopsisdiv>
174
157
<refsect1 id="description">
175
158
<title>DESCRIPTION</title>
177
160
<command>&COMMANDNAME;</command> is a program to generate the
179
<citerefentry><refentrytitle>password-request</refentrytitle>
180
<manvolnum>8mandos</manvolnum></citerefentry>. The keys are
162
<citerefentry><refentrytitle>mandos-client</refentrytitle>
163
<manvolnum>8mandos</manvolnum></citerefentry>. The key is
181
164
normally written to /etc/mandos for later installation into the
182
initrd image, but this, like most things, can be changed with
183
command line options.
165
initrd image, but this, and most other things, can be changed
166
with command line options.
169
This program can also be used with the
170
<option>--password</option> option to generate a ready-made
171
section for <filename>clients.conf</filename> (see
172
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
173
<manvolnum>5</manvolnum></citerefentry>).
187
177
<refsect1 id="purpose">
188
178
<title>PURPOSE</title>
191
180
The purpose of this is to enable <emphasis>remote and unattended
192
181
rebooting</emphasis> of client host computer with an
193
182
<emphasis>encrypted root file system</emphasis>. See <xref
194
183
linkend="overview"/> for details.
199
187
<refsect1 id="options">
200
188
<title>OPTIONS</title>
204
<term><literal>-h</literal>, <literal>--help</literal></term>
192
<term><option>--help</option></term>
193
<term><option>-h</option></term>
207
196
Show a help message and exit
213
<term><literal>-d</literal>, <literal>--dir
214
<replaceable>directory</replaceable></literal></term>
203
<replaceable>DIRECTORY</replaceable></option></term>
205
<replaceable>DIRECTORY</replaceable></option></term>
217
Target directory for key files.
208
Target directory for key files. Default is
209
<filename>/etc/mandos</filename>.
223
<term><literal>-t</literal>, <literal>--type
224
<replaceable>type</replaceable></literal></term>
216
<replaceable>TYPE</replaceable></option></term>
218
<replaceable>TYPE</replaceable></option></term>
227
221
Key type. Default is <quote>DSA</quote>.
233
<term><literal>-l</literal>, <literal>--length
234
<replaceable>bits</replaceable></literal></term>
227
<term><option>--length
228
<replaceable>BITS</replaceable></option></term>
230
<replaceable>BITS</replaceable></option></term>
237
Key length in bits. Default is 1024.
233
Key length in bits. Default is 2048.
243
<term><literal>-s</literal>, <literal>--subtype
244
<replaceable>type</replaceable></literal></term>
239
<term><option>--subtype
240
<replaceable>KEYTYPE</replaceable></option></term>
242
<replaceable>KEYTYPE</replaceable></option></term>
247
245
Subkey type. Default is <quote>ELG-E</quote> (Elgamal
297
<term><literal>-f</literal>, <literal>--force</literal></term>
300
Force overwriting old keys.
303
<term><option>--force</option></term>
304
<term><option>-f</option></term>
307
Force overwriting old key.
312
<term><option>--password</option></term>
313
<term><option>-p</option></term>
316
Prompt for a password and encrypt it with the key already
317
present in either <filename>/etc/mandos</filename> or the
318
directory specified with the <option>--dir</option>
319
option. Outputs, on standard output, a section suitable
320
for inclusion in <citerefentry><refentrytitle
321
>mandos-clients.conf</refentrytitle><manvolnum
322
>8</manvolnum></citerefentry>. The host name or the name
323
specified with the <option>--name</option> option is used
324
for the section header. All other options are ignored,
325
and no key is created.
307
332
<refsect1 id="overview">
308
333
<title>OVERVIEW</title>
309
334
<xi:include href="overview.xml"/>
311
336
This program is a small utility to generate new OpenPGP keys for
337
new Mandos clients, and to generate sections for inclusion in
338
<filename>clients.conf</filename> on the server.
316
342
<refsect1 id="exit_status">
317
343
<title>EXIT STATUS</title>
319
The exit status will be 0 if new keys were successfully created,
345
The exit status will be 0 if a new key (or password, if the
346
<option>--password</option> option was used) was successfully
347
created, otherwise not.
389
415
Normal invocation needs no options:
392
<userinput>mandos-keygen</userinput>
418
<userinput>&COMMANDNAME;</userinput>
394
420
</informalexample>
395
421
<informalexample>
397
Create keys in another directory and of another type. Force
423
Create key in another directory and of another type. Force
398
424
overwriting old key files:
402
428
<!-- do not wrap this line -->
403
<userinput>mandos-keygen --dir ~/keydir --type RSA --force</userinput>
429
<userinput>&COMMANDNAME; --dir ~/keydir --type RSA --force</userinput>
435
Prompt for a password, encrypt it with the key in
436
<filename>/etc/mandos</filename> and output a section suitable
437
for <filename>clients.conf</filename>.
440
<userinput>&COMMANDNAME; --password</userinput>
445
Prompt for a password, encrypt it with the key in the
446
<filename>client-key</filename> directory and output a section
447
suitable for <filename>clients.conf</filename>.
451
<!-- do not wrap this line -->
452
<userinput>&COMMANDNAME; --password --dir client-key</userinput>
406
455
</informalexample>
409
458
<refsect1 id="security">
410
459
<title>SECURITY</title>
412
461
The <option>--type</option>, <option>--length</option>,
413
462
<option>--subtype</option>, and <option>--sublength</option>
414
options can be used to create keys of insufficient security. If
415
in doubt, leave them to the default values.
463
options can be used to create keys of low security. If in
464
doubt, leave them to the default values.
418
The key expire time is not guaranteed to be honored by
419
<citerefentry><refentrytitle>mandos</refentrytitle>
467
The key expire time is <emphasis>not</emphasis> guaranteed to be
468
honored by <citerefentry><refentrytitle>mandos</refentrytitle>
420
469
<manvolnum>8</manvolnum></citerefentry>.
424
473
<refsect1 id="see_also">
425
474
<title>SEE ALSO</title>
427
<citerefentry><refentrytitle>password-request</refentrytitle>
428
<manvolnum>8mandos</manvolnum></citerefentry>,
476
<citerefentry><refentrytitle>gpg</refentrytitle>
477
<manvolnum>1</manvolnum></citerefentry>,
478
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
479
<manvolnum>5</manvolnum></citerefentry>,
429
480
<citerefentry><refentrytitle>mandos</refentrytitle>
430
481
<manvolnum>8</manvolnum></citerefentry>,
431
<citerefentry><refentrytitle>gpg</refentrytitle>
432
<manvolnum>1</manvolnum></citerefentry>
482
<citerefentry><refentrytitle>mandos-client</refentrytitle>
483
<manvolnum>8mandos</manvolnum></citerefentry>
488
<!-- Local Variables: -->
489
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
490
<!-- time-stamp-end: "[\"']>" -->
491
<!-- time-stamp-format: "%:y-%02m-%02d" -->