Re: man isakmpd typos

"Felipe Alfaro Solana" <[email protected]> Mon, 27 Oct 2008 13:00:45 +0100
Newsgroups gmane.os.openbsd.ipv6
Message-ID <[email protected]>
On Mon, Oct 27, 2008 at 12:55 PM, Paul de Weerd <[email protected]> wrote:
> Hi Felipe,
>
> On Mon, Oct 27, 2008 at 12:36:17PM +0100, Felipe Alfaro Solana wrote:
> | On Mon, Oct 27, 2008 at 8:30 AM, Stuart Henderson <[email protected]> wrote:
> | > On 2008/10/27 02:19, Felipe Alfaro Solana wrote:
> | >>
> | >>                 # openssl req -new -key /etc/isakmpd/private/local.key \
> | >>                         -out /etc/isakmpd/private/10.0.0.1.csr
> | >>
> | >> I think the command is wrong. The "-key" command-line argument tells
> | >> OpenSSL where the existing RSA private key is located. However, since
> | >> we are requesting a new CSR and they key does not exist yet
> | >
> | > It is created by /etc/rc at system startup.
> |
> | You are totally right. I killed that file when configuring isakmpd.
> |
> | But, wouldn't it be nice to add a comment to the manual page about how
> | local.key is generated by /etc/rc? It might prevent dumb people like
> | me, that removed the local.key file, from getting funny error messages
> | in the command-line when they are not familiar with OpenSSL?
>
> A reboot will get you this file back (well, not exactly the same
> file). This is mentioned in the documentation of isakpmd(8) :

Yes, that's for sure.

Also, some people might want to use bigger keys (like 2,048 bits),
that's why I thought that mentioning how the local.key file is created
might be worth it. It's not a big deal, though, as it's just a matter
of searching a bit (and running openssl genrsa). But for people not
familiar with OpenSSL it could save a bit of time.

Just my 2 Swiss Francs :)

>     /etc/isakmpd/private/
>             The directory where local private keys used for public
>             key authentication are kept.  By default, the system
>             startup script rc(8) generates a key-pair when starting,
>             if one does not already exist.

Turns out that I didn't read the manual page very well, as this is
already mentioned.

-- 
http://www.felipe-alfaro.org/blog/disclaimer/