X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?a=blobdiff_plain;f=README;h=e23701c9151dc4d946523914dbbf81b2a69251fa;hb=7e311a0bf071a2fb1fc6857a9e9828b8c8f7da54;hp=05b073fd72988c7121db7a1f2a742a546ba24dc5;hpb=db10dcc854450232187cec829c60dac619344d50;p=secnet.git diff --git a/README b/README index 05b073f..e23701c 100644 --- a/README +++ b/README @@ -393,17 +393,18 @@ site: dict argument resolver (resolver closure) random (randomsrc closure) key-cache (privcache closure) - local-key (rsaprivkey closure): Deprecated; use key-cache instead. + local-key (sigprivkey closure): Deprecated; use key-cache instead. address (string list): optional, DNS name(s) used to find our peer; address literals are supported too if enclosed in `[' `]'. port (integer): mandatory if 'address' is specified: the port used to contact our peer peer-keys (string): path (prefix) for peer public key set file(s); - see README.make-secnet-sites re `pub' etc. - key (rsapubkey closure): our peer's public key (obsolete) + see README.make-secnet-sites re `pub' etc. and NOTES.peer-keys. + key (sigpubkey closure): our peer's public key (obsolete) transform (transform closure): how to mangle packets sent between sites dh (dh closure) - hash (hash closure) + hash (hash closure): used for keys whose algorithm (or public + or private key file) does not imply the hash function key-lifetime (integer): max lifetime of a session key, in ms [one hour; mobile: 2 days] setup-retries (integer): max number of times to transmit a key negotiation @@ -576,12 +577,21 @@ priv-cache: dict argument privkey-max (integer): optional, maximum size of private key file in bytes. [4095] +** pubkeys + +Defines: + make-public (closure => sigpubkey closure) + +make-public: ( + arg1: sigscheme name + arg2: base91s encoded public key data, according to algorithm + ** rsa Defines: sigscheme algorithm 00 "rsa1" - rsa-private (closure => rsaprivkey closure) - rsa-public (closure => rsapubkey closure) + rsa-private (closure => sigprivkey closure) + rsa-public (closure => sigpubkey closure) rsa1 sigscheme algorithm: private key: SSH private key file, version 1, no password