Skip to content

Commit

Permalink
Fix SSL boilerplate descriptions in manpages.
Browse files Browse the repository at this point in the history
Some of the SSL boilerplate was specific to switches, but it was included
in OVSDB programs also.  Make it more generic.  Also document SSL options
in some manpages where they were missing.
  • Loading branch information
blp committed Aug 19, 2010
1 parent a946ed3 commit 812560d
Show file tree
Hide file tree
Showing 8 changed files with 25 additions and 8 deletions.
2 changes: 1 addition & 1 deletion lib/ssl-bootstrap.man
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ for bootstrapping.
This option is only useful if the SSL peer sends its CA certificate as
part of the SSL certificate chain. The SSL protocol does not require
the server to send the CA certificate, but
\fBovs\-controller\fR(8) can be configured to do so with the
\fB\*(SN\fR(8) can be configured to do so with the
\fB\-\-peer\-ca\-cert\fR option.
.IP
This option is mutually exclusive with \fB\-C\fR and
Expand Down
13 changes: 7 additions & 6 deletions lib/ssl-peer-ca-cert.man
Original file line number Diff line number Diff line change
@@ -1,12 +1,13 @@
.IP "\fB\-\-peer\-ca\-cert=\fIpeer-cacert.pem\fR"
Specifies a PEM file that contains one or more additional certificates
to send to SSL peers. \fIpeer-cacert.pem\fR should be the CA
certificate used to sign the \fB\*(PN\fR own certificate (the
certificate specified on \fB\-c\fR or \fB\-\-certificate\fR).
certificate used to sign \fB\*(PN\fR's own certificate, that is, the
certificate specified on \fB\-c\fR or \fB\-\-certificate\fR. If
\fB\*(PN\fR's certificate is self-signed, then \fB\-\-certificate\fR
and \fB\-\-peer\-ca\-cert\fR should specify the same file.
.IP
This option is not useful in normal operation, because the SSL peer
must already have the CA certificate for the peer to have any
confidence in \fB\*(PN\fR's identity. However, this option allows a
newly installed switch to obtain the peer CA certificate on first boot
using, e.g., the \fB\-\-bootstrap\-ca\-cert\fR option to
\fBovs\-openflowd\fR(8).
confidence in \fB\*(PN\fR's identity. However, this offers a way for
a new installation to bootstrap the CA certificate on its first SSL
connection.
2 changes: 1 addition & 1 deletion lib/ssl-syn.man
Original file line number Diff line number Diff line change
Expand Up @@ -3,4 +3,4 @@
.br
[\fB\-\-certificate=\fIcert.pem\fR]
.br
[\fB\-\-ca\-cert=\fIswitch\-cacert.pem\fR]
[\fB\-\-ca\-cert=\fIcacert.pem\fR]
3 changes: 3 additions & 0 deletions ovsdb/ovsdb-client.1.in
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,10 @@
..
.\" -*- nroff -*-
.TH ovsdb\-client 1 "November 2009" "Open vSwitch" "Open vSwitch Manual"
.\" This program's name:
.ds PN ovsdb\-client
.\" SSL peer program's name:
.ds SN ovsdb\-server
.
.SH NAME
ovsdb\-client \- command-line interface to \fBovsdb-server\fR(1)
Expand Down
2 changes: 2 additions & 0 deletions ovsdb/ovsdb-server.1.in
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,8 @@ ovsdb\-server \- Open vSwitch database server
[\fB\-\-run=\fIcommand\fR]
.so lib/daemon-syn.man
.so lib/vlog-syn.man
.so lib/ssl-syn.man
.so lib/ssl-bootstrap-syn.man
.so lib/unixctl-syn.man
.so lib/common-syn.man
.
Expand Down
3 changes: 3 additions & 0 deletions utilities/ovs-openflowd.8.in
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
.TH ovs\-openflowd 8 "March 2009" "Open vSwitch" "Open vSwitch Manual"
.\" This program's name:
.ds PN ovs\-openflowd
.\" SSL peer program's name:
.ds SN ovs\-controller
.
.SH NAME
ovs\-openflowd \- OpenFlow switch implementation
Expand Down
5 changes: 5 additions & 0 deletions utilities/ovs-vsctl.8.in
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,10 @@
. RE
..
.TH ovs\-vsctl 8 "November 2009" "Open vSwitch" "Open vSwitch Manual"
.\" This program's name:
.ds PN ovs\-vsctl
.\" SSL peer program's name:
.ds SN ovsdb\-server
.
.SH NAME
ovs\-vsctl \- utility for querying and configuring \fBovs\-vswitchd\fR
Expand Down Expand Up @@ -123,6 +126,8 @@ not used, \fBovs\-vsctl\fR uses a timeout of five seconds.
.
.SS "Public Key Infrastructure Options"
.so lib/ssl.man
.so lib/ssl-bootstrap.man
.so lib/ssl-peer-ca-cert.man
.so lib/vlog.man
.
.SH COMMANDS
Expand Down
3 changes: 3 additions & 0 deletions vswitchd/ovs-vswitchd.8.in
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,10 @@
. IP "\\$1"
..
.TH ovs\-vswitchd 8 "June 2009" "Open vSwitch" "Open vSwitch Manual"
.\" This program's name:
.ds PN ovs\-vswitchd
.\" SSL peer program's name:
.ds SN ovs\-controller
.
.SH NAME
ovs\-vswitchd \- Open vSwitch daemon
Expand Down

0 comments on commit 812560d

Please sign in to comment.