summaryrefslogtreecommitdiff
path: root/sbin/ipsecctl/ipsec.conf.5
diff options
context:
space:
mode:
authorReyk Floeter <reyk@cvs.openbsd.org>2006-01-16 23:57:21 +0000
committerReyk Floeter <reyk@cvs.openbsd.org>2006-01-16 23:57:21 +0000
commit8507d5ed84a7c901a192d08a29970726415afa65 (patch)
treefc0b39eded2b01ba40687e6a318b2ca680655ad7 /sbin/ipsecctl/ipsec.conf.5
parentb7ffe7e87ee21e1dff5302e470d7b9490c931053 (diff)
add support for pre-shared keys with "ike esp" using the new keyword
"psk". rsa-sig is recommended and will still be used by default. ok hshoexer@, manpage ok jmc@
Diffstat (limited to 'sbin/ipsecctl/ipsec.conf.5')
-rw-r--r--sbin/ipsecctl/ipsec.conf.517
1 files changed, 10 insertions, 7 deletions
diff --git a/sbin/ipsecctl/ipsec.conf.5 b/sbin/ipsecctl/ipsec.conf.5
index 3e5e8f80644..31bb7879546 100644
--- a/sbin/ipsecctl/ipsec.conf.5
+++ b/sbin/ipsecctl/ipsec.conf.5
@@ -1,4 +1,4 @@
-.\" $OpenBSD: ipsec.conf.5,v 1.28 2005/12/06 14:27:57 markus Exp $
+.\" $OpenBSD: ipsec.conf.5,v 1.29 2006/01/16 23:57:20 reyk Exp $
.\"
.\" Copyright (c) 2004 Mathieu Sauve-Frankel All rights reserved.
.\"
@@ -391,14 +391,17 @@ as the identity of the local peer.
Similar to
.Ar srcid ,
this optional parameter defines a FQDN to be used by the remote peer.
-.El
-.Pp
-Note that
-.Xr isakmpd 8
-will use RSA authentication.
+.It Ar psk Aq Ar string
+Use a pre-shared key
+.Ar string
+for authentication.
+If not specified, RSA authentication will be used.
By default, the system startup script
.Xr rc 8
-generates a key-pair when starting, if one does not already exist.
+generates a key-pair for
+.Xr isakmpd 8
+when starting, if one does not already exist.
+.El
.Pp
See also
.Sx ISAKMP EXAMPLES