📄 newhostkey.8
字号:
.TH IPSEC_NEWHOSTKEY 8 "4 March 2002".\" RCSID $Id: newhostkey.8,v 1.5 2002/04/24 07:36:09 mcr Exp $.SH NAMEipsec newhostkey \- generate a new host authentication key.SH SYNOPSIS.B ipsec.B newhostkey.B \-\-outputfilename[.B \-\-quiet].B \e.br.in +10[.B \-\-bitsn][.B \-\-hostnamehost].SH DESCRIPTION.I Newhostkeyoutputs (into.IR filename ,which can be `\fB-\fR' for standard output)an RSA private key suitable for this host,in.IR /etc/ipsec.secretsformat(see.IR ipsec.secrets (5)).Normally,.I newhostkeyinvokes.IR rsasigkey(see.IR ipsec_rsasigkey (8))with the.B \-\-verboseoption, so a narrative of what is being done appears on standard error..PPThe.B \-\-outputspecifier, although it is syntactically an option and can appear atany point among the options (it doesn't have to be first),is not optional.The specified.I filenameis created under umask.B 077if nonexistent;if it already exists and is non-empty,a warning message about that is sent to standard error,and the output is appended to the file..PPThe.B \-\-quietoption suppresses both the.IR rsasigkeynarrative and the existing-file warning message..PPThe.B \-\-bitsoption specifies the number of bits in the key;the current default is 2192 and we do not recommend use of anythingshorter unless unusual constraints demand it..PPThe.B \-\-hostnameoption is passed through to.IR rsasigkeyto tell it what host name to label the output with(via its.B \-\-hostnameoption)..PPThe output format is that of.IR rsasigkey ,with bracketing added to complete the.I ipsec.secretsformat.In the usual case, where.I ipsec.secretscontains only the host's own private key,the output of.I newhostkeyis sufficient as a complete.I ipsec.secretsfile..SH SEE ALSOipsec.secrets(5), ipsec_rsasigkey(8).SH HISTORYWritten for the Linux FreeS/WAN project<http://www.freeswan.org>by Henry Spencer..SH BUGSAs with.IR rsasigkey ,the run time is difficult to predict,since depletion of the system's randomness pool can causearbitrarily long waits for random bits,and the prime-number searches can also take unpredictable(and potentially large) amounts of CPU time.See.IR ipsec_rsasigkey (8)for some typical performance numbers..PPA higher-level tool which could handle the clerical detailsof changing to a new key would be helpful..PPThe requirement for.B \-\-outputis a blemish,but private keys are extremely sensitive informationand unusual precautions seem justified.
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -