{"id":3575,"date":"2022-12-20T17:09:03","date_gmt":"2022-12-20T20:09:03","guid":{"rendered":"http:\/\/lode.uno\/linux-man\/index.php\/2022\/12\/20\/ipsec_showhostkey-man8\/"},"modified":"2022-12-20T17:09:03","modified_gmt":"2022-12-20T20:09:03","slug":"ipsec_showhostkey-man8","status":"publish","type":"post","link":"https:\/\/lode.uno\/linux-man\/2022\/12\/20\/ipsec_showhostkey-man8\/","title":{"rendered":"IPSEC_SHOWHOSTKEY (man8)"},"content":{"rendered":"<h1 align=\"center\">IPSEC_SHOWHOSTKEY<\/h1>\n<p> <a href=\"#NAME\">NAME<\/a><br \/> <a href=\"#SYNOPSIS\">SYNOPSIS<\/a><br \/> <a href=\"#DESCRIPTION\">DESCRIPTION<\/a><br \/> <a href=\"#DIAGNOSTICS\">DIAGNOSTICS<\/a><br \/> <a href=\"#FILES\">FILES<\/a><br \/> <a href=\"#SEE ALSO\">SEE ALSO<\/a><br \/> <a href=\"#HISTORY\">HISTORY<\/a><br \/> <a href=\"#BUGS\">BUGS<\/a><br \/> <a href=\"#AUTHOR\">AUTHOR<\/a> <\/p>\n<hr>\n<h2>NAME <a name=\"NAME\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">ipsec_showhostkey \u2212 show host&#8217;s authentication key<\/p>\n<h2>SYNOPSIS <a name=\"SYNOPSIS\"><\/a> <\/h2>\n<table width=\"100%\" border=\"0\" rules=\"none\" frame=\"void\" cellspacing=\"0\" cellpadding=\"0\">\n<tr valign=\"top\" align=\"left\">\n<td width=\"11%\"><\/td>\n<td width=\"89%\">\n<p style=\"margin-top: 1em\"><b>ipsec<\/b> <i>showhostkey<\/i> [\u2212\u2212verbose] {\u2212\u2212version\u00a0|\u00a0\u2212\u2212list\u00a0|\u00a0\u2212\u2212dump\u00a0|\u00a0\u2212\u2212left\u00a0|\u00a0\u2212\u2212right\u00a0|\u00a0\u2212\u2212ipseckey}<\/p>\n<\/td>\n<\/tr>\n<\/table>\n<p style=\"margin-left:20%;\">[\u2212\u2212ckaid\u00a0<i>ckaid\u00a0<\/i>|\u00a0\u2212\u2212rsaid\u00a0<i>rsaid<\/i>] <br \/> [\u2212\u2212gateway\u00a0<i>gateway<\/i>] [\u2212\u2212precedence\u00a0<i>precedence<\/i>] <br \/> [\u2212\u2212nssdir\u00a0<i>nssdir<\/i>] [\u2212\u2212password\u00a0<i>password<\/i>]<\/p>\n<h2>DESCRIPTION <a name=\"DESCRIPTION\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\"><i>Showhostkey<\/i> outputs (on standard output) a public key suitable for this host, in the format specified, using the host key information stored in the NSS database.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\">In general, since only the super\u2212user can access the NSS database, only the super\u2212user can display the public key information.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>Common Options <br \/> \u2212\u2212version<\/b><\/p>\n<p style=\"margin-left:17%;\">Print the libreswan version, then exit.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212verbose<\/b><\/p>\n<p style=\"margin-left:17%;\">Increase the verbosity.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212nssdir<\/b> <i>nssdir<\/i><\/p>\n<p style=\"margin-left:17%;\">Specify the libreswan directory that contains the NSS database (default \/var\/lib\/ipsec\/nss).<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212password<\/b> <i>password<\/i><\/p>\n<p style=\"margin-left:17%;\">Specify the password to use when accessing the NSS database (default contained in \/etc\/ipsec.d\/nsspassword).<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>List Options <br \/> \u2212\u2212list<\/b><\/p>\n<p style=\"margin-left:17%;\">List the private keys.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212dump<\/b><\/p>\n<p style=\"margin-left:17%;\">List, with more details, the private keys.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>Public Key Options <br \/> \u2212\u2212ckaid<\/b> <i>ckaid<\/i><\/p>\n<p style=\"margin-left:17%;\">Select the public key to display using the NSS ckaid.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212rsaid<\/b> <i>rsaid<\/i><\/p>\n<p style=\"margin-left:17%;\">Select the public key to display using the RSA key ID.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212left<\/b>, <b>\u2212\u2212right<\/b><\/p>\n<p style=\"margin-left:17%;\">Print the selected public key in <b>ipsec.conf<\/b>(5) format, as a <b>leftrsasigkey<\/b> or <b>rightrsasigkey<\/b> parameter respectively. For example, <b>\u2212\u2212left<\/b> might give (with the key data trimmed down for clarity):<\/p>\n<p style=\"margin-left:23%; margin-top: 1em\">leftrsasigkey=0sAQOF8tZ2&#8230;+buFuFn\/<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212ipseckey<\/b><\/p>\n<p style=\"margin-left:17%;\">Print the selected public key in a format suitable for use as opportunistic\u2212encryption DNS IPSECKEY record format (RFC 4025). A gateway can be specified with the <b>\u2212\u2212gateway<\/b>, which currently supports IPv4 and IPv6 addresses. For the host name, the value returned by <i>gethostname<\/i> is used, with a <b>.<\/b> appended.<\/p>\n<p style=\"margin-left:17%; margin-top: 1em\">For example, <b>\u2212\u2212ipseckey \u2212\u2212gateway 10.11.12.13<\/b> might give (with the key data trimmed for clarity):<\/p>\n<p style=\"margin-left:23%; margin-top: 1em\">IN IPSECKEY 10 1 2 10.11.12.13 AQOF8tZ2&#8230;+buFuFn\/&#8221;<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212gateway<\/b> <i>gateway<\/i><\/p>\n<p style=\"margin-left:17%;\">For <b>\u2212\u2212ipseckey<\/b>, specify the <i>gateway<\/i> to display with the DNS IPSECKEY record.<\/p>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>\u2212\u2212precedence<\/b> <i>precedence<\/i><\/p>\n<p style=\"margin-left:17%;\">For <b>\u2212\u2212ipseckey<\/b>, specify the <i>precedence<\/i> to display with the DNS IPSECKEY record.<\/p>\n<h2>DIAGNOSTICS <a name=\"DIAGNOSTICS\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">A complaint about \u201cno pubkey line found\u201d indicates that the host has a key but it was generated with an old version of FreeS\/WAN and does not contain the information that <i>showhostkey<\/i> needs.<\/p>\n<h2>FILES <a name=\"FILES\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">\/var\/lib\/ipsec\/nss, \/etc\/ipsec.d\/nsspassword<\/p>\n<h2>SEE ALSO <a name=\"SEE ALSO\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\"><b>ipsec.conf<\/b>(5), <b>ipsec rsasigkey<\/b>(8) <b>ipsec newhostkey<\/b>(8)<\/p>\n<h2>HISTORY <a name=\"HISTORY\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\">Written for the Linux FreeS\/WAN project <<b><font color=\"#0000FF\">https:\/\/www.freeswan.org<\/font><\/b><font color=\"#000000\">> by Henry Spencer. Updated by Paul Wouters for the IPSECKEY format.<\/font><\/p>\n<h2>BUGS <a name=\"BUGS\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\"><font color=\"#000000\">Arguably, rather than just reporting the no\u2212IN\u2212KEY\u2212line\u2212found problem, <i>showhostkey<\/i> should be smart enough to run the existing key through <i>rsasigkey<\/i> with the <b>\u2212\u2212oldkey<\/b> option, to generate a suitable output line.<\/font><\/p>\n<h2>AUTHOR <a name=\"AUTHOR\"><\/a> <\/h2>\n<p style=\"margin-left:11%; margin-top: 1em\"><font color=\"#000000\"><b>Paul Wouters<\/b><\/font><\/p>\n<p style=\"margin-left:17%;\"><font color=\"#000000\">placeholder to suppress warning<\/font><\/p>\n<hr>\n","protected":false},"excerpt":{"rendered":"<p>  ipsec_showhostkey \u2212 show host&#8217;s authentication key <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[5,52,693,4],"class_list":["post-3575","post","type-post","status-publish","format-standard","hentry","category-8-administracion-del-sistema","tag-5","tag-administracion","tag-ipsec_showhostkey","tag-man8"],"gutentor_comment":0,"_links":{"self":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts\/3575","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/comments?post=3575"}],"version-history":[{"count":0,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/posts\/3575\/revisions"}],"wp:attachment":[{"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/media?parent=3575"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/categories?post=3575"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lode.uno\/linux-man\/wp-json\/wp\/v2\/tags?post=3575"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}