Re: man isakmpd typos

Stuart Henderson <[email protected]> Mon, 27 Oct 2008 11:46:19 +0000
Newsgroups gmane.os.openbsd.ipv6
Message-ID <[email protected]>
On 2008/10/27 12:36, Felipe Alfaro Solana wrote:
> On Mon, Oct 27, 2008 at 8:30 AM, Stuart Henderson <[email protected]> wrote:
> > On 2008/10/27 02:19, Felipe Alfaro Solana wrote:
> >>
> >>                 # openssl req -new -key /etc/isakmpd/private/local.key \
> >>                         -out /etc/isakmpd/private/10.0.0.1.csr
> >>
> >> I think the command is wrong. The "-key" command-line argument tells
> >> OpenSSL where the existing RSA private key is located. However, since
> >> we are requesting a new CSR and they key does not exist yet
> >
> > It is created by /etc/rc at system startup.
> 
> You are totally right. I killed that file when configuring isakmpd.
> 
> But, wouldn't it be nice to add a comment to the manual page about how
> local.key is generated by /etc/rc? It might prevent dumb people like
> me, that removed the local.key file, from getting funny error messages
> in the command-line when they are not familiar with OpenSSL?

I don't know, ssh manuals don't go into detail about how to fix
things when you remove the host keys, etc.. I think it's expected
that if you remove a system configuration file you should know
what you're letting yourself in for.