66
46
<refname><command>&COMMANDNAME;</command></refname>
68
Generate keys for <citerefentry><refentrytitle>password-request
69
</refentrytitle><manvolnum>8mandos</manvolnum></citerefentry>
48
Generate key and password for Mandos client and server.
75
54
<command>&COMMANDNAME;</command>
77
<arg choice="plain"><option>--dir</option>
78
<replaceable>directory</replaceable></arg>
81
<arg choice="plain"><option>--type</option>
82
<replaceable>type</replaceable></arg>
85
<arg choice="plain"><option>--length</option>
86
<replaceable>bits</replaceable></arg>
89
<arg choice="plain"><option>--subtype</option>
90
<replaceable>type</replaceable></arg>
93
<arg choice="plain"><option>--sublength</option>
94
<replaceable>bits</replaceable></arg>
97
<arg choice="plain"><option>--name</option>
98
<replaceable>NAME</replaceable></arg>
101
<arg choice="plain"><option>--email</option>
102
<replaceable>EMAIL</replaceable></arg>
105
<arg choice="plain"><option>--comment</option>
106
<replaceable>COMMENT</replaceable></arg>
109
<arg choice="plain"><option>--expire</option>
110
<replaceable>TIME</replaceable></arg>
113
<arg choice="plain"><option>--force</option></arg>
117
<command>&COMMANDNAME;</command>
119
<arg choice="plain"><option>-d</option>
120
<replaceable>directory</replaceable></arg>
123
<arg choice="plain"><option>-t</option>
124
<replaceable>type</replaceable></arg>
127
<arg choice="plain"><option>-l</option>
128
<replaceable>bits</replaceable></arg>
131
<arg choice="plain"><option>-s</option>
132
<replaceable>type</replaceable></arg>
135
<arg choice="plain"><option>-L</option>
136
<replaceable>bits</replaceable></arg>
139
<arg choice="plain"><option>-n</option>
140
<replaceable>NAME</replaceable></arg>
143
<arg choice="plain"><option>-e</option>
144
<replaceable>EMAIL</replaceable></arg>
147
<arg choice="plain"><option>-c</option>
148
<replaceable>COMMENT</replaceable></arg>
151
<arg choice="plain"><option>-x</option>
152
<replaceable>TIME</replaceable></arg>
155
<arg choice="plain"><option>-f</option></arg>
56
<arg choice="plain"><option>--dir
57
<replaceable>DIRECTORY</replaceable></option></arg>
58
<arg choice="plain"><option>-d
59
<replaceable>DIRECTORY</replaceable></option></arg>
63
<arg choice="plain"><option>--type
64
<replaceable>KEYTYPE</replaceable></option></arg>
65
<arg choice="plain"><option>-t
66
<replaceable>KEYTYPE</replaceable></option></arg>
70
<arg choice="plain"><option>--length
71
<replaceable>BITS</replaceable></option></arg>
72
<arg choice="plain"><option>-l
73
<replaceable>BITS</replaceable></option></arg>
77
<arg choice="plain"><option>--subtype
78
<replaceable>KEYTYPE</replaceable></option></arg>
79
<arg choice="plain"><option>-s
80
<replaceable>KEYTYPE</replaceable></option></arg>
84
<arg choice="plain"><option>--sublength
85
<replaceable>BITS</replaceable></option></arg>
86
<arg choice="plain"><option>-L
87
<replaceable>BITS</replaceable></option></arg>
91
<arg choice="plain"><option>--name
92
<replaceable>NAME</replaceable></option></arg>
93
<arg choice="plain"><option>-n
94
<replaceable>NAME</replaceable></option></arg>
98
<arg choice="plain"><option>--email
99
<replaceable>ADDRESS</replaceable></option></arg>
100
<arg choice="plain"><option>-e
101
<replaceable>ADDRESS</replaceable></option></arg>
105
<arg choice="plain"><option>--comment
106
<replaceable>TEXT</replaceable></option></arg>
107
<arg choice="plain"><option>-c
108
<replaceable>TEXT</replaceable></option></arg>
112
<arg choice="plain"><option>--expire
113
<replaceable>TIME</replaceable></option></arg>
114
<arg choice="plain"><option>-x
115
<replaceable>TIME</replaceable></option></arg>
118
<arg><option>--force</option></arg>
159
121
<command>&COMMANDNAME;</command>
160
122
<group choice="req">
123
<arg choice="plain"><option>--password</option></arg>
161
124
<arg choice="plain"><option>-p</option></arg>
162
<arg choice="plain"><option>--password</option></arg>
165
<arg choice="plain"><option>--dir</option>
166
<replaceable>directory</replaceable></arg>
169
<arg choice="plain"><option>--name</option>
170
<replaceable>NAME</replaceable></arg>
125
<arg choice="plain"><option>--passfile
126
<replaceable>FILE</replaceable></option></arg>
127
<arg choice="plain"><option>-F</option>
128
<replaceable>FILE</replaceable></arg>
132
<arg choice="plain"><option>--dir
133
<replaceable>DIRECTORY</replaceable></option></arg>
134
<arg choice="plain"><option>-d
135
<replaceable>DIRECTORY</replaceable></option></arg>
139
<arg choice="plain"><option>--name
140
<replaceable>NAME</replaceable></option></arg>
141
<arg choice="plain"><option>-n
142
<replaceable>NAME</replaceable></option></arg>
174
146
<command>&COMMANDNAME;</command>
175
147
<group choice="req">
148
<arg choice="plain"><option>--help</option></arg>
176
149
<arg choice="plain"><option>-h</option></arg>
177
<arg choice="plain"><option>--help</option></arg>
181
153
<command>&COMMANDNAME;</command>
182
154
<group choice="req">
155
<arg choice="plain"><option>--version</option></arg>
183
156
<arg choice="plain"><option>-v</option></arg>
184
<arg choice="plain"><option>--version</option></arg>
187
159
</refsynopsisdiv>
189
161
<refsect1 id="description">
190
162
<title>DESCRIPTION</title>
192
164
<command>&COMMANDNAME;</command> is a program to generate the
194
<citerefentry><refentrytitle>password-request</refentrytitle>
195
<manvolnum>8mandos</manvolnum></citerefentry>. The keys are
166
<citerefentry><refentrytitle>mandos-client</refentrytitle>
167
<manvolnum>8mandos</manvolnum></citerefentry>. The key is
196
168
normally written to /etc/mandos for later installation into the
197
initrd image, but this, like most things, can be changed with
198
command line options.
169
initrd image, but this, and most other things, can be changed
170
with command line options.
201
It can also be used to generate ready-made sections for
173
This program can also be used with the
174
<option>--password</option> or <option>--passfile</option>
175
options to generate a ready-made section for
176
<filename>clients.conf</filename> (see
202
177
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
203
<manvolnum>5</manvolnum></citerefentry> using the
204
<option>--password</option> option.
178
<manvolnum>5</manvolnum></citerefentry>).
208
182
<refsect1 id="purpose">
209
183
<title>PURPOSE</title>
212
185
The purpose of this is to enable <emphasis>remote and unattended
213
186
rebooting</emphasis> of client host computer with an
214
187
<emphasis>encrypted root file system</emphasis>. See <xref
215
188
linkend="overview"/> for details.
220
192
<refsect1 id="options">
221
193
<title>OPTIONS</title>
225
<term><literal>-h</literal>, <literal>--help</literal></term>
197
<term><option>--help</option></term>
198
<term><option>-h</option></term>
228
201
Show a help message and exit
234
<term><literal>-d</literal>, <literal>--dir
235
<replaceable>directory</replaceable></literal></term>
208
<replaceable>DIRECTORY</replaceable></option></term>
210
<replaceable>DIRECTORY</replaceable></option></term>
238
213
Target directory for key files. Default is
429
432
Normal invocation needs no options:
432
<userinput>mandos-keygen</userinput>
435
<userinput>&COMMANDNAME;</userinput>
434
437
</informalexample>
435
438
<informalexample>
437
Create keys in another directory and of another type. Force
440
Create key in another directory and of another type. Force
438
441
overwriting old key files:
442
445
<!-- do not wrap this line -->
443
<userinput>mandos-keygen --dir ~/keydir --type RSA --force</userinput>
446
<userinput>&COMMANDNAME; --dir ~/keydir --type RSA --force</userinput>
452
Prompt for a password, encrypt it with the key in
453
<filename>/etc/mandos</filename> and output a section suitable
454
for <filename>clients.conf</filename>.
457
<userinput>&COMMANDNAME; --password</userinput>
462
Prompt for a password, encrypt it with the key in the
463
<filename>client-key</filename> directory and output a section
464
suitable for <filename>clients.conf</filename>.
468
<!-- do not wrap this line -->
469
<userinput>&COMMANDNAME; --password --dir client-key</userinput>
446
472
</informalexample>
449
475
<refsect1 id="security">
450
476
<title>SECURITY</title>
452
478
The <option>--type</option>, <option>--length</option>,
453
479
<option>--subtype</option>, and <option>--sublength</option>
454
options can be used to create keys of insufficient security. If
455
in doubt, leave them to the default values.
480
options can be used to create keys of low security. If in
481
doubt, leave them to the default values.
458
The key expire time is not guaranteed to be honored by
459
<citerefentry><refentrytitle>mandos</refentrytitle>
484
The key expire time is <emphasis>not</emphasis> guaranteed to be
485
honored by <citerefentry><refentrytitle>mandos</refentrytitle>
460
486
<manvolnum>8</manvolnum></citerefentry>.
464
490
<refsect1 id="see_also">
465
491
<title>SEE ALSO</title>
467
<citerefentry><refentrytitle>password-request</refentrytitle>
468
<manvolnum>8mandos</manvolnum></citerefentry>,
493
<citerefentry><refentrytitle>gpg</refentrytitle>
494
<manvolnum>1</manvolnum></citerefentry>,
495
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
496
<manvolnum>5</manvolnum></citerefentry>,
469
497
<citerefentry><refentrytitle>mandos</refentrytitle>
470
498
<manvolnum>8</manvolnum></citerefentry>,
471
<citerefentry><refentrytitle>gpg</refentrytitle>
472
<manvolnum>1</manvolnum></citerefentry>
499
<citerefentry><refentrytitle>mandos-client</refentrytitle>
500
<manvolnum>8mandos</manvolnum></citerefentry>
505
<!-- Local Variables: -->
506
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
507
<!-- time-stamp-end: "[\"']>" -->
508
<!-- time-stamp-format: "%:y-%02m-%02d" -->