pki: Add pki --req man page

This commit is contained in:
Tobias Brunner
2013-09-13 15:07:35 +02:00
parent 96aa5a1ddd
commit bb8e2e1759
5 changed files with 98 additions and 5 deletions
+1
View File
@@ -1496,6 +1496,7 @@ AC_CONFIG_FILES([
src/pki/man/ipsec-pki.8
src/pki/man/pki---gen.8
src/pki/man/pki---issue.8
src/pki/man/pki---req.8
src/pki/man/pki---self.8
src/pki/man/pki---signcrl.8
])
+2 -3
View File
@@ -174,9 +174,8 @@ static void __attribute__ ((constructor))reg()
command_register((command_t) {
req, 'r', "req",
"create a PKCS#10 certificate request",
{"[--in file] [--type rsa|ecdsa]",
" --dn distinguished-name [--san subjectAltName]+",
"[--password challengePassword]",
{" [--in file] [--type rsa|ecdsa] --dn distinguished-name",
"[--san subjectAltName]+ [--password challengePassword]",
"[--digest md5|sha1|sha224|sha256|sha384|sha512] [--outform der|pem]"},
{
{"help", 'h', 0, "show usage information"},
+2 -1
View File
@@ -3,6 +3,7 @@ man8_MANS = \
pki---gen.8 \
pki---self.8 \
pki---issue.8 \
pki---signcrl.8
pki---signcrl.8 \
pki---req.8
CLEANFILES = $(man8_MANS)
+2 -1
View File
@@ -73,4 +73,5 @@ Verify a certificate using a CA certificate.
.BR pki\ \-\-gen (8),
.BR pki\ \-\-self (8),
.BR pki\ \-\-issue (8),
.BR pki\ \-\-signcrl (8)
.BR pki\ \-\-signcrl (8),
.BR pki\ \-\-req (8)
+91
View File
@@ -0,0 +1,91 @@
.TH "PKI \-\-REQ" 8 "2013-07-31" "@PACKAGE_VERSION@" "strongSwan"
.
.SH "NAME"
.
pki \-\-req \- Create a PKCS#10 certificate request
.
.SH "SYNOPSIS"
.
.SY pki\ \-\-req
.OP \-\-in file
.OP \-\-type type
.BI \-\-dn\~ distinguished-name
.OP \-\-san subjectAltName
.OP \-\-password password
.OP \-\-digest digest
.OP \-\-outform encoding
.OP \-\-debug level
.YS
.
.SY pki\ \-\-req
.BI \-\-options\~ file
.YS
.
.SY "pki \-\-req"
.B \-h
|
.B \-\-help
.YS
.
.SH "DESCRIPTION"
.
This sub-command of
.BR ipsec\-pki (8)
is used to create a PKCS#10 certificate request.
.
.SH "OPTIONS"
.
.TP
.B "\-h, \-\-help"
Print usage information with a summary of the available options.
.TP
.BI "\-v, \-\-debug " level
Set debug level, default: 1.
.TP
.BI "\-+, \-\-options " file
Read command line options from \fIfile\fR.
.TP
.BI "\-i, \-\-in " file
Private key input file. If not given the key is read from \fISTDIN\fR.
.TP
.BI "\-t, \-\-type " type
Type of the input key. Either \fIrsa\fR or \fIecdsa\fR, defaults to \fIrsa\fR.
.TP
.BI "\-d, \-\-dn " distinguished-name
Subject distinguished name (DN). Required.
.TP
.BI "\-a, \-\-san " subjectAltName
subjectAltName extension to include in request. Can be used multiple times.
.TP
.BI "\-p, \-\-password " password
The challengePassword to include in the certificate request.
.TP
.BI "\-g, \-\-digest " digest
Digest to use for signature creation. One of \fImd5\fR, \fIsha1\fR,
\fIsha224\fR, \fIsha256\fR, \fIsha384\fR, or \fIsha512\fR. Defaults to
\fIsha1\fR.
.TP
.BI "\-f, \-\-outform " encoding
Encoding of the created certificate file. Either \fIder\fR (ASN.1 DER) or
\fIpem\fR (Base64 PEM), defaults to \fIder\fR.
.
.SH "EXAMPLES"
.
Generate a certificate request for an RSA key, with a subjectAltName extension:
.PP
.EX
ipsec pki \-\-req \-\-in key.der \-\-dn "C=CH, O=strongSwan, CN=moon" \\
\-\-san [email protected] > req.der
.EE
.PP
Generate a certificate request for an ECDSA key and a different digest:
.PP
.EX
ipsec pki \-\-req \-\-in key.der \-\-type ecdsa \-\-digest sha256 \\
\-\-dn "C=CH, O=strongSwan, CN=carol" > req.der
.EE
.PP
.
.SH "SEE ALSO"
.
.BR ipsec\-pki (8)