Re: man isakmpd typos

"Felipe Alfaro Solana" <[email protected]> Mon, 27 Oct 2008 12:36:17 +0100
Newsgroups gmane.os.openbsd.ipv6
Message-ID <[email protected]>
On Mon, Oct 27, 2008 at 8:30 AM, Stuart Henderson <[email protected]> wrote:
> On 2008/10/27 02:19, Felipe Alfaro Solana wrote:
>>
>>                 # openssl req -new -key /etc/isakmpd/private/local.key \
>>                         -out /etc/isakmpd/private/10.0.0.1.csr
>>
>> I think the command is wrong. The "-key" command-line argument tells
>> OpenSSL where the existing RSA private key is located. However, since
>> we are requesting a new CSR and they key does not exist yet
>
> It is created by /etc/rc at system startup.

You are totally right. I killed that file when configuring isakmpd.

But, wouldn't it be nice to add a comment to the manual page about how
local.key is generated by /etc/rc? It might prevent dumb people like
me, that removed the local.key file, from getting funny error messages
in the command-line when they are not familiar with OpenSSL?

-- 
http://www.felipe-alfaro.org/blog/disclaimer/