66
46
<refname><command>&COMMANDNAME;</command></refname>
68
Generate keys for <citerefentry><refentrytitle>password-request
69
</refentrytitle><manvolnum>8mandos</manvolnum></citerefentry>
48
Generate key and password for Mandos client and server.
75
54
<command>&COMMANDNAME;</command>
77
<arg choice="plain"><option>--dir</option>
78
<replaceable>directory</replaceable></arg>
81
<arg choice="plain"><option>--type</option>
82
<replaceable>type</replaceable></arg>
85
<arg choice="plain"><option>--length</option>
86
<replaceable>bits</replaceable></arg>
89
<arg choice="plain"><option>--name</option>
90
<replaceable>NAME</replaceable></arg>
93
<arg choice="plain"><option>--email</option>
94
<replaceable>EMAIL</replaceable></arg>
97
<arg choice="plain"><option>--comment</option>
98
<replaceable>COMMENT</replaceable></arg>
101
<arg choice="plain"><option>--expire</option>
102
<replaceable>TIME</replaceable></arg>
105
<arg choice="plain"><option>--force</option></arg>
109
<command>&COMMANDNAME;</command>
111
<arg choice="plain"><option>-d</option>
112
<replaceable>directory</replaceable></arg>
115
<arg choice="plain"><option>-t</option>
116
<replaceable>type</replaceable></arg>
119
<arg choice="plain"><option>-l</option>
120
<replaceable>bits</replaceable></arg>
123
<arg choice="plain"><option>-n</option>
124
<replaceable>NAME</replaceable></arg>
127
<arg choice="plain"><option>-e</option>
128
<replaceable>EMAIL</replaceable></arg>
131
<arg choice="plain"><option>-c</option>
132
<replaceable>COMMENT</replaceable></arg>
135
<arg choice="plain"><option>-x</option>
136
<replaceable>TIME</replaceable></arg>
139
<arg choice="plain"><option>-f</option></arg>
143
<command>&COMMANDNAME;</command>
145
<arg choice='plain'><option>-h</option></arg>
146
<arg choice='plain'><option>--help</option></arg>
150
<command>&COMMANDNAME;</command>
152
<arg choice='plain'><option>-v</option></arg>
153
<arg choice='plain'><option>--version</option></arg>
56
<arg choice="plain"><option>--dir
57
<replaceable>DIRECTORY</replaceable></option></arg>
58
<arg choice="plain"><option>-d
59
<replaceable>DIRECTORY</replaceable></option></arg>
63
<arg choice="plain"><option>--type
64
<replaceable>KEYTYPE</replaceable></option></arg>
65
<arg choice="plain"><option>-t
66
<replaceable>KEYTYPE</replaceable></option></arg>
70
<arg choice="plain"><option>--length
71
<replaceable>BITS</replaceable></option></arg>
72
<arg choice="plain"><option>-l
73
<replaceable>BITS</replaceable></option></arg>
77
<arg choice="plain"><option>--subtype
78
<replaceable>KEYTYPE</replaceable></option></arg>
79
<arg choice="plain"><option>-s
80
<replaceable>KEYTYPE</replaceable></option></arg>
84
<arg choice="plain"><option>--sublength
85
<replaceable>BITS</replaceable></option></arg>
86
<arg choice="plain"><option>-L
87
<replaceable>BITS</replaceable></option></arg>
91
<arg choice="plain"><option>--name
92
<replaceable>NAME</replaceable></option></arg>
93
<arg choice="plain"><option>-n
94
<replaceable>NAME</replaceable></option></arg>
98
<arg choice="plain"><option>--email
99
<replaceable>ADDRESS</replaceable></option></arg>
100
<arg choice="plain"><option>-e
101
<replaceable>ADDRESS</replaceable></option></arg>
105
<arg choice="plain"><option>--comment
106
<replaceable>TEXT</replaceable></option></arg>
107
<arg choice="plain"><option>-c
108
<replaceable>TEXT</replaceable></option></arg>
112
<arg choice="plain"><option>--expire
113
<replaceable>TIME</replaceable></option></arg>
114
<arg choice="plain"><option>-x
115
<replaceable>TIME</replaceable></option></arg>
118
<arg><option>--force</option></arg>
121
<command>&COMMANDNAME;</command>
123
<arg choice="plain"><option>--password</option></arg>
124
<arg choice="plain"><option>-p</option></arg>
128
<arg choice="plain"><option>--dir
129
<replaceable>DIRECTORY</replaceable></option></arg>
130
<arg choice="plain"><option>-d
131
<replaceable>DIRECTORY</replaceable></option></arg>
135
<arg choice="plain"><option>--name
136
<replaceable>NAME</replaceable></option></arg>
137
<arg choice="plain"><option>-n
138
<replaceable>NAME</replaceable></option></arg>
142
<command>&COMMANDNAME;</command>
144
<arg choice="plain"><option>--help</option></arg>
145
<arg choice="plain"><option>-h</option></arg>
149
<command>&COMMANDNAME;</command>
151
<arg choice="plain"><option>--version</option></arg>
152
<arg choice="plain"><option>-v</option></arg>
156
155
</refsynopsisdiv>
158
157
<refsect1 id="description">
159
158
<title>DESCRIPTION</title>
161
160
<command>&COMMANDNAME;</command> is a program to generate the
163
<citerefentry><refentrytitle>password-request</refentrytitle>
164
<manvolnum>8mandos</manvolnum></citerefentry>. The keys are
162
<citerefentry><refentrytitle>mandos-client</refentrytitle>
163
<manvolnum>8mandos</manvolnum></citerefentry>. The key is
165
164
normally written to /etc/mandos for later installation into the
166
initrd image, but this, like most things, can be changed with
167
command line options.
165
initrd image, but this, and most other things, can be changed
166
with command line options.
169
This program can also be used with the
170
<option>--password</option> option to generate a ready-made
171
section for <filename>clients.conf</filename> (see
172
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
173
<manvolnum>5</manvolnum></citerefentry>).
171
177
<refsect1 id="purpose">
172
178
<title>PURPOSE</title>
175
180
The purpose of this is to enable <emphasis>remote and unattended
176
181
rebooting</emphasis> of client host computer with an
177
182
<emphasis>encrypted root file system</emphasis>. See <xref
178
183
linkend="overview"/> for details.
183
187
<refsect1 id="options">
184
188
<title>OPTIONS</title>
188
<term><literal>-h</literal>, <literal>--help</literal></term>
192
<term><option>--help</option></term>
193
<term><option>-h</option></term>
191
196
Show a help message and exit
197
<term><literal>-d</literal>, <literal>--dir
198
<replaceable>directory</replaceable></literal></term>
201
Target directory for key files.
207
<term><literal>-t</literal>, <literal>--type
208
<replaceable>type</replaceable></literal></term>
211
Key type. Default is DSA.
217
<term><literal>-l</literal>, <literal>--length
218
<replaceable>bits</replaceable></literal></term>
221
Key length in bits. Default is 1024.
227
<term><literal>-e</literal>, <literal>--email</literal>
228
<replaceable>address</replaceable></term>
203
<replaceable>DIRECTORY</replaceable></option></term>
205
<replaceable>DIRECTORY</replaceable></option></term>
208
Target directory for key files. Default is
209
<filename>/etc/mandos</filename>.
216
<replaceable>TYPE</replaceable></option></term>
218
<replaceable>TYPE</replaceable></option></term>
221
Key type. Default is <quote>DSA</quote>.
227
<term><option>--length
228
<replaceable>BITS</replaceable></option></term>
230
<replaceable>BITS</replaceable></option></term>
233
Key length in bits. Default is 2048.
239
<term><option>--subtype
240
<replaceable>KEYTYPE</replaceable></option></term>
242
<replaceable>KEYTYPE</replaceable></option></term>
245
Subkey type. Default is <quote>ELG-E</quote> (Elgamal
252
<term><option>--sublength
253
<replaceable>BITS</replaceable></option></term>
255
<replaceable>BITS</replaceable></option></term>
258
Subkey length in bits. Default is 2048.
264
<term><option>--email
265
<replaceable>ADDRESS</replaceable></option></term>
267
<replaceable>ADDRESS</replaceable></option></term>
231
270
Email address of key. Default is empty.
237
<term><literal>-c</literal>, <literal>--comment</literal>
238
<replaceable>comment</replaceable></term>
276
<term><option>--comment
277
<replaceable>TEXT</replaceable></option></term>
279
<replaceable>TEXT</replaceable></option></term>
241
282
Comment field for key. The default value is
242
"<literal>Mandos client key</literal>".
283
<quote><literal>Mandos client key</literal></quote>.
248
<term><literal>-x</literal>, <literal>--expire</literal>
249
<replaceable>time</replaceable></term>
289
<term><option>--expire
290
<replaceable>TIME</replaceable></option></term>
292
<replaceable>TIME</replaceable></option></term>
252
295
Key expire time. Default is no expiration. See
352
415
Normal invocation needs no options:
355
<userinput>mandos-keygen</userinput>
418
<userinput>&COMMANDNAME;</userinput>
357
420
</informalexample>
358
421
<informalexample>
360
Create keys in another directory and of another type. Force
423
Create key in another directory and of another type. Force
361
424
overwriting old key files:
365
428
<!-- do not wrap this line -->
366
<userinput>mandos-keygen --dir ~/keydir --type RSA --force</userinput>
429
<userinput>&COMMANDNAME; --dir ~/keydir --type RSA --force</userinput>
435
Prompt for a password, encrypt it with the key in
436
<filename>/etc/mandos</filename> and output a section suitable
437
for <filename>clients.conf</filename>.
440
<userinput>&COMMANDNAME; --password</userinput>
445
Prompt for a password, encrypt it with the key in the
446
<filename>client-key</filename> directory and output a section
447
suitable for <filename>clients.conf</filename>.
451
<!-- do not wrap this line -->
452
<userinput>&COMMANDNAME; --password --dir client-key</userinput>
369
455
</informalexample>
372
458
<refsect1 id="security">
373
459
<title>SECURITY</title>
375
The <option>--type</option> and <option>--length</option>
376
options can be used to create keys of insufficient security. If
377
in doubt, leave them to the default values.
461
The <option>--type</option>, <option>--length</option>,
462
<option>--subtype</option>, and <option>--sublength</option>
463
options can be used to create keys of low security. If in
464
doubt, leave them to the default values.
380
The key expire time is not guaranteed to be honored by
381
<citerefentry><refentrytitle>mandos</refentrytitle>
467
The key expire time is <emphasis>not</emphasis> guaranteed to be
468
honored by <citerefentry><refentrytitle>mandos</refentrytitle>
382
469
<manvolnum>8</manvolnum></citerefentry>.
386
473
<refsect1 id="see_also">
387
474
<title>SEE ALSO</title>
389
<citerefentry><refentrytitle>password-request</refentrytitle>
390
<manvolnum>8mandos</manvolnum></citerefentry>,
391
<citerefentry><refentrytitle>mandos</refentrytitle>
392
<manvolnum>8</manvolnum></citerefentry>, and
393
476
<citerefentry><refentrytitle>gpg</refentrytitle>
394
<manvolnum>1</manvolnum></citerefentry>
477
<manvolnum>1</manvolnum></citerefentry>,
478
<citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
479
<manvolnum>5</manvolnum></citerefentry>,
480
<citerefentry><refentrytitle>mandos</refentrytitle>
481
<manvolnum>8</manvolnum></citerefentry>,
482
<citerefentry><refentrytitle>mandos-client</refentrytitle>
483
<manvolnum>8mandos</manvolnum></citerefentry>
488
<!-- Local Variables: -->
489
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
490
<!-- time-stamp-end: "[\"']>" -->
491
<!-- time-stamp-format: "%:y-%02m-%02d" -->