Signed-off-by: Selva Nair <selva.nair@gmail.com>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Message-Id: <20210822152820.7072-1-selva.nair@gmail.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg22747.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
| ... | ... |
@@ -58,7 +58,7 @@ Implementation |
| 58 | 58 |
When setting up a tls-crypt-v2 group (similar to generating a tls-crypt or |
| 59 | 59 |
tls-auth key previously): |
| 60 | 60 |
|
| 61 |
-1. Generate a tls-crypt-v2 server key using OpenVPN's ``--tls-crypt-v2-genkey server``. |
|
| 61 |
+1. Generate a tls-crypt-v2 server key using OpenVPN's ``--genkey tls-crypt-v2-server``. |
|
| 62 | 62 |
This key contains 2 512-bit keys, of which we use: |
| 63 | 63 |
|
| 64 | 64 |
* the first 256 bits of key 1 as AES-256-CTR encryption key ``Ke`` |
| ... | ... |
@@ -73,7 +73,7 @@ tls-auth key previously): |
| 73 | 73 |
|
| 74 | 74 |
When provisioning a client, create a client-specific tls-crypt key: |
| 75 | 75 |
|
| 76 |
-1. Generate 2048 bits client-specific key ``Kc`` using OpenVPN's ``--tls-crypt-v2-genkey client`` |
|
| 76 |
+1. Generate 2048 bits client-specific key ``Kc`` using OpenVPN's ``--genkey tls-crypt-v2-client`` |
|
| 77 | 77 |
|
| 78 | 78 |
2. Optionally generate metadata |
| 79 | 79 |
|
| ... | ... |
@@ -614,7 +614,7 @@ static const char usage_message[] = |
| 614 | 614 |
" see --secret option for more info.\n" |
| 615 | 615 |
"--tls-crypt-v2 key : For clients: use key as a client-specific tls-crypt key.\n" |
| 616 | 616 |
" For servers: use key to decrypt client-specific keys. For\n" |
| 617 |
- " key generation (--tls-crypt-v2-genkey): use key to\n" |
|
| 617 |
+ " key generation (--genkey tls-crypt-v2-client): use key to\n" |
|
| 618 | 618 |
" encrypt generated client-specific key. (See --tls-crypt.)\n" |
| 619 | 619 |
"--genkey tls-crypt-v2-client [keyfile] [base64 metadata]: Generate a\n" |
| 620 | 620 |
" fresh tls-crypt-v2 client key, and store to\n" |