| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586 | .TH tor-gencert 1 "" Jan-2008 "".\" manual page by Nick Mathewson.SH NAME.LPtor-gencert \- Generate certs and keys for Tor directory authorities.SH SYNOPSIS\fBtor-gencert\fP\ [-h|--help] [-v] [-r|--reuse] [--create-identity-key] [-i \fIid_file\fP] [-c \fIcert_file\fP] [-m \fInum\fP] [-a \fIaddress\fP:\fIport\fP].SH DESCRIPTION\fBtor-gencert\fR generates certificates and private keys for use by Tordirectory authorities running the v3 Tor directory protocol, as used by Tor0.2.0 and later.  If you are not running a directory authority, you don'tneed to use tor-gencert..PPEvery directory authority has a long term authority \fIidentity key\fP (whichis distinct from the identity key it uses as a Tor server); this key shouldbe kept offline in a secure location.  It is used to certify shorter-lived\fIsigning keys\fP, which are kept online and used by the directory authorityto sign votes and consensus documents..PPAfter you use this program to generate a signing key and a certificate, copythose files to the keys subdirectory of your Tor process, and send Tor aSIGHUP signal. DO NOT COPY THE IDENTITY KEY..SH OPTIONS\fB-v\fPDisplay verbose output..LP.TP\fB-h\fP or \fB--help\fPDisplay help text and exit..LP.TP\fB-r\fP or \fB--reuse\fPGenerate a new certificate, but not a new signing key.  This can beused to change the address or lifetime associated with a given key..LP.TP\fB--create-identity-key\fPGenerate a new identity key.  You should only use this option the firsttime you run tor-gencert; in the future, you should use the identitykey that's already there..LP.TP\fB-i \fR\fIFILENAME\fPRead the identity key from the specified file.  If the file is not presentand --create-identity-key is provided, create the identity key in thespecified file.  Default: "./authority_identity_key".LP.TP\fB-s \fR\fIFILENAME\fPWrite the signing key to the specified file.  Default:"./authority_signing_key".LP.TP\fB-c \fR\fIFILENAME\fPWrite the certificate to the specified file.Default: "./authority_certificate".LP.TP\fB-m \fR\fINUM\fPNumber of months that the certificate should be valid.  Default: 12..LP.TP\fB--passphrase-fd \fR\fIFILEDES\fPFiledescriptor to read the file descriptor from.  Ends at the firstNUL or newline.  Default: read from the terminal..LP.TP\fB-a \fR\fIaddress\fR:\fIport\fPIf provided, advertise the address:port combination as this authority'spreferred directory port in its certificate.  If the address is a hostname,the hostname is resolved to an IP before it's published..SH BUGSThis probably doesn't run on Windows.  That's not a big issue, since wedon't really want authorities to be running on Windows anyway..SH SEE ALSO.BR tor (1).PPSee also the "dir-spec.txt" file, distributed with Tor..SH AUTHORSRoger Dingledine <arma@mit.edu>, Nick Mathewson <nickm@alum.mit.edu>.
 |