[Pkg-fedora-ds-maintainers] [libapache2-mod-nss] 122/156: Bugzilla Bug #906082 - mod_nss requires manpages for gencert and nss_pcache.

Timo Aaltonen tjaalton-guest at moszumanska.debian.org
Wed Jul 2 13:55:34 UTC 2014


This is an automated email from the git hooks/post-receive script.

tjaalton-guest pushed a commit to branch master
in repository libapache2-mod-nss.

commit b8bc6feef62b4822b1ec30862ad8f045c428f3f2
Author: Matthew Harmsen <mharmsen at redhat.com>
Date:   Tue Jul 2 10:24:10 2013 -0700

    Bugzilla Bug #906082 - mod_nss requires manpages for gencert and nss_pcache.
---
 gencert.8    | 54 +++++++++++++++++++++++++------------
 nss_pcache.8 | 87 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
 2 files changed, 124 insertions(+), 17 deletions(-)

diff --git a/gencert.8 b/gencert.8
index 0e44601..f2017c3 100644
--- a/gencert.8
+++ b/gencert.8
@@ -14,26 +14,46 @@
 .\"
 .\" Author: Rob Crittenden <rcritten at redhat.com>
 .\"
-.TH "gencert" "8" "Feb 2 2011" "Rob Crittenden" ""
+.TH "gencert" "8" "Jul 1 2013" "Rob Crittenden" ""
 .SH "NAME"
 gencert \- Generate a test NSS database for mod_nss
-.SH "SYNOPSIS"
-gencert \fIDIRECTORY\fR
-.SH "DESCRIPTION"
-A tool to generate self\-signed CA as well as server and user certificates for mod_nss testing.
-
-This is used to generate a default NSS database for the mod_nss Apache module. It does not test to see if an existing database already exists so use with care.
 
-gencert will generate a new NSS database and set an empty database password.
+.SH "SYNOPSIS"
+gencert <destdir>
 
+.SH "DESCRIPTION"
+A tool used to generate a self\-signed CA as well as server and user certificates for mod_nss testing.
+.PP
+This is used to generate a default NSS database for the mod_nss Apache module. It does not test to see if an existing database already exists, so use with care.
+.PP
+\fBgencert\fP will generate a new NSS database and set an empty database password.
+.PP
 It generates a self\-signed CA with the subject "CN=Certificate Shack, O=example.com, C=US"
-
-It also generates a certificate suitable for servers with the subject "CN=FQDN, O=example.com, C=US" and a user certificate with the subject "E=alpha at FQDN, CN=Frank Alpha, UID=alpha, OU=People, O=example.com, C=US".
-
+.PP
+It also generates a certificate suitable for servers with the subject "CN=<FQDN>, O=example.com, C=US", and a user certificate with the subject "E=alpha@<FQDN>, CN=Frank Alpha, UID=alpha, OU=People, O=example.com, C=US".
+.PP
 The nicknames it uses are:
-
-CA: cacert
-
-Server certificate: Server\-Cert
-
-User cert: alpha
+.IP
+.TS
+tab(;);
+ll,ll.
+CA:;cacert
+Server certificate:;Server\-Cert
+User cert:;alpha
+.TE
+
+.SH OPTIONS
+.TP
+.B <destdir>
+Specifies the destination directory where the NSS databases will be created.
+
+.SH BUGS
+Report bugs to http://bugzilla.redhat.com.
+
+.SH AUTHORS
+Rob Crittenden <rcritten at redhat.com>.
+
+.SH COPYRIGHT
+Copyright (c) 2011 Red Hat, Inc. This is licensed under the Apache License, Version 2.0 (the "License"); no one may use this file except in compliance with the License. A copy of this license is available at http://www.apache.org/licenses/LICENSE-2.0.
+.PP
+Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.  See the License for the specific language governing permissions and limitations under the License.
diff --git a/nss_pcache.8 b/nss_pcache.8
new file mode 100644
index 0000000..0e50d85
--- /dev/null
+++ b/nss_pcache.8
@@ -0,0 +1,87 @@
+.\" A man page for nss_pcache
+.\"
+.\" Licensed under the Apache License, Version 2.0 (the "License");
+.\" you may not use this file except in compliance with the License.
+.\" You may obtain a copy of the License at
+.\"
+.\"      http://www.apache.org/licenses/LICENSE-2.0
+.\"
+.\" Unless required by applicable law or agreed to in writing, software
+.\" distributed under the License is distributed on an "AS IS" BASIS,
+.\" WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+.\" See the License for the specific language governing permissions and
+.\" limitations under the License.
+.\"
+.\" Author: Rob Crittenden <rcritten at redhat.com>
+.\"
+.TH "nss_pcache" "8" "Jul 1 2013" "Rob Crittenden" ""
+.SH "NAME"
+nss_pcache \- Helper program used to store token password pins
+
+.SH "SYNOPSIS"
+nss_pcache <semid> <fips on/off> <directory> [prefix]
+
+.SH "DESCRIPTION"
+A helper program used by the Apache \fBhttpd\fP mod_nss plug-in to store the NSS PKCS #11 token password pins between restarts of Apache.
+.PP
+Whenever an Apache \fBhttpd\fP process configured to use the mod_nss plug-in is started, this program will be automatically invoked via reference to the mod_nss configuration file stored under \fB/etc/httpd/conf.d/nss.conf\fP which contains the following default entry:
+.IP
+#   Pass Phrase Helper:
+.br
+#   This helper program stores the token password pins between
+.br
+#   restarts of Apache.
+.br
+NSSPassPhraseHelper /usr/sbin/nss_pcache
+
+.SH OPTIONS
+.TP
+.B <semid>
+The semaphore which corresponds to the mod_nss plug-in registered with the Apache \fBhttpd\fP process during startup.
+.TP
+.B <fips on/off>
+Specifies whether FIPS mode should be enabled, \fBon\fP, or disabled, \fBoff\fP.  By default, FIPS mode is disabled, and no variable is specified in \fB/etc/httpd/conf.d/nss.conf\fP.  To enable FIPS mode, establish password access for the specified NSS security databases, and specify the following variable in  \fB/etc/httpd/conf.d/nss.conf\fP:
+.IP
+.TS
+tab(;);
+ll,ll.
+;NSSFIPS on
+.TE
+.TP
+.B <directory>
+Specifies the destination directory of the NSS databases that will be associated with this executable specified by the following entry in \fB/etc/httpd/conf.d/nss.conf\fP:
+.IP
+.TS
+tab(;);
+ll,ll.
+;#   Server Certificate Database:
+;#   The NSS security database directory that holds the
+;#   certificates and keys. The database consists
+;#   of 3 files: cert8.db, key3.db and secmod.db.
+;#   Provide the directory that these files exist.
+;NSSCertificateDatabase /etc/httpd/alias
+.TE
+.TP
+.B [prefix]
+Optional prefix to attach prior to the names of the NSS certificate and key databases contained in the directory referenced by the previous argument and specified by the following entry in \fB/etc/httpd/conf.d/nss.conf\fP (must be uncommented in order to be utilized):
+.IP
+.TS
+tab(;);
+ll,ll.
+;#   Database Prefix:
+;#   In order to be able to store multiple NSS databases
+;#   in one directory they need unique names. This option
+;#   sets the database prefix used for cert8.db and key3.db.
+;#NSSDBPrefix my-prefix-
+.TE
+
+.SH BUGS
+Report bugs to http://bugzilla.redhat.com.
+
+.SH AUTHORS
+Rob Crittenden <rcritten at redhat.com>.
+
+.SH COPYRIGHT
+Copyright (c) 2013 Red Hat, Inc. This is licensed under the Apache License, Version 2.0 (the "License"); no one may use this file except in compliance with the License. A copy of this license is available at http://www.apache.org/licenses/LICENSE-2.0.
+.PP
+Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.  See the License for the specific language governing permissions and limitations under the License.

-- 
Alioth's /usr/local/bin/git-commit-notice on /srv/git.debian.org/git/pkg-fedora-ds/libapache2-mod-nss.git



More information about the Pkg-fedora-ds-maintainers mailing list