OpenBSD CVS

CVS log for src/usr.sbin/ikectl/ikectl.8


[BACK] Up to [local] / src / usr.sbin / ikectl

Request diff between arbitrary revisions


Default branch: MAIN


Revision 1.28 / (download) - annotate - [select for diffs], Thu Mar 31 17:27:30 2022 UTC (2 years, 2 months ago) by naddy
Branch: MAIN
CVS Tags: OPENBSD_7_5_BASE, OPENBSD_7_5, OPENBSD_7_4_BASE, OPENBSD_7_4, OPENBSD_7_3_BASE, OPENBSD_7_3, OPENBSD_7_2_BASE, OPENBSD_7_2, OPENBSD_7_1_BASE, OPENBSD_7_1, HEAD
Changes since 1.27: +3 -3 lines
Diff to previous 1.27 (colored)

man pages: add missing commas between subordinate and main clauses

jmc@ dislikes a comma before "then" in a conditional, so leave those
untouched.

ok jmc@

Revision 1.27 / (download) - annotate - [select for diffs], Sat Apr 25 18:38:21 2020 UTC (4 years, 1 month ago) by tobhe
Branch: MAIN
CVS Tags: OPENBSD_7_0_BASE, OPENBSD_7_0, OPENBSD_6_9_BASE, OPENBSD_6_9, OPENBSD_6_8_BASE, OPENBSD_6_8, OPENBSD_6_7_BASE, OPENBSD_6_7
Changes since 1.26: +4 -2 lines
Diff to previous 1.26 (colored)

Document 'ikectl show sa'.

Revision 1.26 / (download) - annotate - [select for diffs], Wed Mar 18 22:12:43 2020 UTC (4 years, 2 months ago) by tobhe
Branch: MAIN
Changes since 1.25: +4 -2 lines
Diff to previous 1.25 (colored)

Add 'ikectl reset id <ID>' command to reset all SAs from policies with
matching destination ID.

ok patrick@ markus@

Revision 1.25 / (download) - annotate - [select for diffs], Mon Nov 2 10:27:44 2015 UTC (8 years, 7 months ago) by jsg
Branch: MAIN
CVS Tags: OPENBSD_6_6_BASE, OPENBSD_6_6, OPENBSD_6_5_BASE, OPENBSD_6_5, OPENBSD_6_4_BASE, OPENBSD_6_4, OPENBSD_6_3_BASE, OPENBSD_6_3, OPENBSD_6_2_BASE, OPENBSD_6_2, OPENBSD_6_1_BASE, OPENBSD_6_1, OPENBSD_6_0_BASE, OPENBSD_6_0, OPENBSD_5_9_BASE, OPENBSD_5_9
Changes since 1.24: +6 -3 lines
Diff to previous 1.24 (colored)

Accept an ocsp option when creating certificates to set the extended
key usage for OCSP signing.

Requested by and ok reyk@

Revision 1.24 / (download) - annotate - [select for diffs], Mon Sep 7 15:24:53 2015 UTC (8 years, 8 months ago) by sobrado
Branch: MAIN
Changes since 1.23: +5 -5 lines
Diff to previous 1.23 (colored)

append a slash immediately after a file system path that is a directory;
uppercase the description of /var/run/iked.sock (found by jmc@);
add missing full stop.

ok jmc@

Revision 1.23 / (download) - annotate - [select for diffs], Mon Jul 27 17:28:39 2015 UTC (8 years, 10 months ago) by sobrado
Branch: MAIN
CVS Tags: OPENBSD_5_8_BASE, OPENBSD_5_8
Changes since 1.22: +6 -6 lines
Diff to previous 1.22 (colored)

use file system path (.Pa) semantic markup macros where appropriate.

ok jmc@

Revision 1.22 / (download) - annotate - [select for diffs], Sat Feb 28 21:51:57 2015 UTC (9 years, 3 months ago) by bentley
Branch: MAIN
CVS Tags: OPENBSD_5_7_BASE, OPENBSD_5_7
Changes since 1.21: +3 -3 lines
Diff to previous 1.21 (colored)

Reduce usage of predefined strings in manpages.

Predefined strings are not very portable across troff implementations,
and they make the source much harder to read. Usually the intended
character can be written directly.

No output changes, except for two instances where the incorrect escape
was used in the first place.

tweaks + ok schwarze@

Revision 1.21 / (download) - annotate - [select for diffs], Tue Jul 16 11:13:33 2013 UTC (10 years, 10 months ago) by schwarze
Branch: MAIN
CVS Tags: OPENBSD_5_6_BASE, OPENBSD_5_6, OPENBSD_5_5_BASE, OPENBSD_5_5, OPENBSD_5_4_BASE, OPENBSD_5_4
Changes since 1.20: +4 -4 lines
Diff to previous 1.20 (colored)

use .Mt for email addresses; from Jan Stary <hans at stare dot cz>; ok jmc@

Revision 1.20 / (download) - annotate - [select for diffs], Tue Jan 8 10:38:19 2013 UTC (11 years, 4 months ago) by reyk
Branch: MAIN
CVS Tags: OPENBSD_5_3_BASE, OPENBSD_5_3
Changes since 1.19: +3 -4 lines
Diff to previous 1.19 (colored)

Remove private CVS tag from an obsolete repository and bump copyright
to 2013 while I'm here... this is my way of saying "happy new year!".

Revision 1.19 / (download) - annotate - [select for diffs], Tue Sep 18 12:07:59 2012 UTC (11 years, 8 months ago) by reyk
Branch: MAIN
Changes since 1.18: +5 -5 lines
Diff to previous 1.18 (colored)

update email addresses to match reality.
sure jsg@ mikeb@

Revision 1.18 / (download) - annotate - [select for diffs], Thu Jan 20 13:58:16 2011 UTC (13 years, 4 months ago) by jmc
Branch: MAIN
CVS Tags: OPENBSD_5_2_BASE, OPENBSD_5_2, OPENBSD_5_1_BASE, OPENBSD_5_1, OPENBSD_5_0_BASE, OPENBSD_5_0, OPENBSD_4_9_BASE, OPENBSD_4_9
Changes since 1.17: +3 -3 lines
Diff to previous 1.17 (colored)

more double word removal;

Revision 1.17 / (download) - annotate - [select for diffs], Mon Oct 11 14:25:05 2010 UTC (13 years, 7 months ago) by sthen
Branch: MAIN
Changes since 1.16: +3 -3 lines
Diff to previous 1.16 (colored)

and another one... s/10.4.5.6/10.3.4.5/, also from jy-p.

Revision 1.16 / (download) - annotate - [select for diffs], Mon Oct 11 13:47:20 2010 UTC (13 years, 7 months ago) by sthen
Branch: MAIN
Changes since 1.15: +2 -2 lines
Diff to previous 1.15 (colored)

typo, s/10.1.2.3/10.2.3.4/, from jy-p

Revision 1.15 / (download) - annotate - [select for diffs], Fri Oct 8 11:51:56 2010 UTC (13 years, 7 months ago) by jsg
Branch: MAIN
Changes since 1.14: +5 -2 lines
Diff to previous 1.14 (colored)

tweak for nroff

Revision 1.14 / (download) - annotate - [select for diffs], Fri Oct 8 10:13:47 2010 UTC (13 years, 7 months ago) by jsg
Branch: MAIN
Changes since 1.13: +11 -8 lines
Diff to previous 1.13 (colored)

allow optional paths for the install commands so we can
install into the isakmpd directory hierarchy for example.

Revision 1.13 / (download) - annotate - [select for diffs], Fri Oct 8 07:45:06 2010 UTC (13 years, 7 months ago) by reyk
Branch: MAIN
Changes since 1.12: +9 -3 lines
Diff to previous 1.12 (colored)

Allow to show certificate details (show ca x cert [y]).

Revision 1.12 / (download) - annotate - [select for diffs], Thu Oct 7 13:30:50 2010 UTC (13 years, 7 months ago) by reyk
Branch: MAIN
Changes since 1.11: +6 -4 lines
Diff to previous 1.11 (colored)

Allow to specify the export password on the command line (optionally, for
scripting).  The "peer" argument now needs to be preceded with the "peer"
keyword, eg. ... export peer 10.1.1.1 instead of export 10.1.1.1.

Revision 1.11 / (download) - annotate - [select for diffs], Thu Oct 7 12:33:58 2010 UTC (13 years, 7 months ago) by reyk
Branch: MAIN
Changes since 1.10: +49 -13 lines
Diff to previous 1.10 (colored)

nroff doesn't like long argument lists that work fine with mandoc.
split them into Xo/Xc blocks to make nroff happy again.

Revision 1.10 / (download) - annotate - [select for diffs], Thu Oct 7 12:23:14 2010 UTC (13 years, 7 months ago) by reyk
Branch: MAIN
Changes since 1.9: +22 -4 lines
Diff to previous 1.9 (colored)

- add a -q (quiet) command line option that will be used by ikeca to
set openssl batch mode: don't ask for x509 options, use the defaults.
- allow to specify the initial ca password on the command line to also
make it scriptable.
- allow to create certificates for clientAuth or serverAuth only
(eg. ikectl ca foo certificate bar server).
- cosmetics: move double declarations of ca_*() functions to parser.h.

ok phessler@

Revision 1.9 / (download) - annotate - [select for diffs], Fri Oct 1 07:08:25 2010 UTC (13 years, 8 months ago) by jmc
Branch: MAIN
Changes since 1.8: +26 -25 lines
Diff to previous 1.8 (colored)

tweak previous;

Revision 1.8 / (download) - annotate - [select for diffs], Thu Sep 30 10:36:24 2010 UTC (13 years, 8 months ago) by reyk
Branch: MAIN
Changes since 1.7: +5 -3 lines
Diff to previous 1.7 (colored)

Add jsg@ to the AUTHORS section of ikectl; he wrote the CA/PKI part.

Revision 1.7 / (download) - annotate - [select for diffs], Thu Sep 30 10:03:52 2010 UTC (13 years, 8 months ago) by reyk
Branch: MAIN
Changes since 1.6: +98 -5 lines
Diff to previous 1.6 (colored)

Add some examples about using the CA commands to create and install the
CA and peers certificates.

With input from mikeb@

Revision 1.6 / (download) - annotate - [select for diffs], Wed Jun 23 16:01:01 2010 UTC (13 years, 11 months ago) by jsg
Branch: MAIN
CVS Tags: OPENBSD_4_8_BASE, OPENBSD_4_8
Changes since 1.5: +21 -1 lines
Diff to previous 1.5 (colored)

Add a ca export command for EAP mode where we only require the CA cert,
and make both export commands optionally take an argument that will be
added to a peer.txt file in the exported output.   Additionally
include any site specific notes from /usr/share/iked if present.

man page bits and help with the parser from reyk

Revision 1.5 / (download) - annotate - [select for diffs], Tue Jun 15 08:41:44 2010 UTC (13 years, 11 months ago) by jsg
Branch: MAIN
Changes since 1.4: +3 -3 lines
Diff to previous 1.4 (colored)

fix an mdoc macro

Revision 1.4 / (download) - annotate - [select for diffs], Mon Jun 14 17:41:18 2010 UTC (13 years, 11 months ago) by jsg
Branch: MAIN
Changes since 1.3: +17 -1 lines
Diff to previous 1.3 (colored)

Add commands to create/delete/install/import keys without
involving certificates as suggested by reyk and don't
recreate private keys if a key already exists.

ok reyk@

Revision 1.3 / (download) - annotate - [select for diffs], Thu Jun 10 16:14:04 2010 UTC (13 years, 11 months ago) by jsg
Branch: MAIN
Changes since 1.2: +7 -3 lines
Diff to previous 1.2 (colored)

Add a command to revoke a certificate and generate a CRL;
make the ca install command install the CRL as well.

discussed with reyk@

Revision 1.2 / (download) - annotate - [select for diffs], Thu Jun 10 14:08:37 2010 UTC (13 years, 11 months ago) by reyk
Branch: MAIN
Changes since 1.1: +17 -1 lines
Diff to previous 1.1 (colored)

add new commands: the couple/decouple commands will set loading of the
learned flows and SAs to the kernel which is useful for testing and
debugging. the active/passive commands are required to use iked
with sasyncd(8);  sasyncd just needs to call "ikectl active/passive" or
send the appropriate imsg to support iked but this is not implemented yet.

Revision 1.1 / (download) - annotate - [select for diffs], Thu Jun 3 16:49:00 2010 UTC (14 years ago) by reyk
Branch: MAIN

Import iked, a new implementation of the IKEv2 protocol.

iked(8) is an automatic keying daemon for IPsec, like isakmpd(8), that
IPsec creates flows and SAs automatically.  Unlike isakmpd, iked(8)
implements the newer IKEv2 protocol instead of IKEv1/ISAKMP.  The
daemon is still work-in-progress and not enabled in the builds, but is
already able to establish IKEv2 sessions with some other IKEv2
implementations as a responder.

with lots of help and debugging by jsg@
ok deraadt@

This form allows you to request diff's between any two revisions of a file. You may select a symbolic revision name using the selection box or you may type in a numeric name using the type-in text box.