Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
* Add a simple man page for tangd-rotate-keys and adjust man page building to allow for some differentiation between different systems - primarily for the tang man page.
- Loading branch information
Showing
4 changed files
with
67 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,4 +1,5 @@ | ||
mans += join_paths(meson.current_source_dir(), 'tang-show-keys.1') | ||
mans += join_paths(meson.current_source_dir(), 'tangd-rotate-keys.1') | ||
mans += join_paths(meson.current_source_dir(), 'tang.8') | ||
|
||
# vim:set ts=2 sw=2 et: |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
tangd-rotate-keys(1) | ||
==================== | ||
:doctype: manpage | ||
|
||
== NAME | ||
|
||
tangd-rotate-keys - Perform rotation of tang keys | ||
|
||
== SYNOPSIS | ||
|
||
*tangd-rotate-keys* [-h] [-v] -d <KEYDIR> | ||
|
||
== DESCRIPTION | ||
|
||
in order to preserve the security of the system over the long run, you need to periodically | ||
rotate your keys. The precise interval at which you should rotate depends upon your application, | ||
key sizes and institutional policy. For some common recommendations, see: https://www.keylength.com. | ||
|
||
*tangd-rotate-keys* generates new keys in the key database directory given by the *-d* option. | ||
This is typically */var/db/tang*. It also rename the old keys to have a leading . in order to | ||
hide them from advertisement. | ||
|
||
Tang will immediately pick up all changes. No restart is required. | ||
|
||
At this point, new client bindings will pick up the new keys and old clients can continue to | ||
utilize the old keys. Once you are sure that all the old clients have been migrated to use the | ||
new keys, you can remove the old keys. Be aware that removing the old keys while clients are | ||
still using them can result in data loss. You have been warned. | ||
|
||
== OPTIONS | ||
* *-d* <KEYDIR>: | ||
The directory with the keys, e.g. /var/db/tang | ||
|
||
* *-h*: | ||
Display the usage information | ||
|
||
* *-v*: | ||
Verbose. Display additional info on keys created/rotated | ||
|
||
== AUTHOR | ||
|
||
Sergio Correia <scorreia@redhat.com> | ||
|
||
== SEE ALSO | ||
|
||
link:tang.8.adoc[*tang*(8)] |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters