Re: man isakmpd typos
Stuart Henderson <[email protected]> Mon, 27 Oct 2008 11:46:19 +0000
| Newsgroups | gmane.os.openbsd.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
On 2008/10/27 12:36, Felipe Alfaro Solana wrote: > On Mon, Oct 27, 2008 at 8:30 AM, Stuart Henderson <[email protected]> wrote: > > On 2008/10/27 02:19, Felipe Alfaro Solana wrote: > >> > >> # openssl req -new -key /etc/isakmpd/private/local.key \ > >> -out /etc/isakmpd/private/10.0.0.1.csr > >> > >> I think the command is wrong. The "-key" command-line argument tells > >> OpenSSL where the existing RSA private key is located. However, since > >> we are requesting a new CSR and they key does not exist yet > > > > It is created by /etc/rc at system startup. > > You are totally right. I killed that file when configuring isakmpd. > > But, wouldn't it be nice to add a comment to the manual page about how > local.key is generated by /etc/rc? It might prevent dumb people like > me, that removed the local.key file, from getting funny error messages > in the command-line when they are not familiar with OpenSSL? I don't know, ssh manuals don't go into detail about how to fix things when you remove the host keys, etc.. I think it's expected that if you remove a system configuration file you should know what you're letting yourself in for.