Re: man isakmpd typos
"Felipe Alfaro Solana" <[email protected]> Mon, 27 Oct 2008 12:36:17 +0100
| Newsgroups | gmane.os.openbsd.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Oct 27, 2008 at 8:30 AM, Stuart Henderson <[email protected]> wrote: > On 2008/10/27 02:19, Felipe Alfaro Solana wrote: >> >> # openssl req -new -key /etc/isakmpd/private/local.key \ >> -out /etc/isakmpd/private/10.0.0.1.csr >> >> I think the command is wrong. The "-key" command-line argument tells >> OpenSSL where the existing RSA private key is located. However, since >> we are requesting a new CSR and they key does not exist yet > > It is created by /etc/rc at system startup. You are totally right. I killed that file when configuring isakmpd. But, wouldn't it be nice to add a comment to the manual page about how local.key is generated by /etc/rc? It might prevent dumb people like me, that removed the local.key file, from getting funny error messages in the command-line when they are not familiar with OpenSSL? -- http://www.felipe-alfaro.org/blog/disclaimer/