Re: Feature request: ipsec showhostkey --reverse

Sam Sgro <[email protected]> Wed, 5 Mar 2003 16:54:01 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


On Wed, 5 Mar 2003, Claudia Schmeing wrote:

> In a Live User Test of doc/quickstart.html, I discovered we could
> make life easier for our users by having an option like:
> 
> 
> 	ipsec showhostkey --reverse 192.0.2.11
> 
> which would produce a reverse DNS record suitable for that IP, eg.
> (key shortened for clarity):
> 
> 	; RSA 2048 bits   xy.example.com   Sat Apr 15 13:53:22 2000
> 	11.2.0.192.in-addr.arpa.   IN   KEY   0x4200 4 1 AQOF8tZ2...+buFuFn

The new "mailkey" script provides exactly this functionality; it will format
your KEY/TXT records as you describe, depending on whether you call it for
"--forward" or "--reverse". It dumps the output to a script, which will 
contain the data.

I can't see a reason why that functionality shouldn't be moved to showhostkey.

- -- 
Sam Sgro
[email protected]

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv
Comment: For the matching public key, finger the Reply-To: address.

iQCVAwUBPmZx+0OSC4btEQUtAQF4YgP/YU4+0ZTkcJZ+MGt5Lc44WPX+MowKczvv
5TLLnD7xKwMfcHF0zQ2iNBwoTHcVEs5564vLzoSMoXj7OYdA3KsqAnOuJzu2gW7a
gBOOp0DG7t6+CtQS1wpNzHPsy0E9qTFdenC4x6nCCOFthpnuhN8GPgTBcmvWzehX
LT6SiW6dMLI=
=dln9
-----END PGP SIGNATURE-----