    bcfg2-crypt — Bcfg2 1.3.0 documentation
    <div class="document">
      <div class="documentwrapper">
        <div class="bodywrapper">
          <div class="body">
  <div class="section" id="bcfg2-crypt">
<h1>bcfg2-crypt<a class="headerlink" href="#bcfg2-crypt" title="Permalink to this headline">¶</a></h1>
<div class="section" id="synopsis">
<h2>Synopsis<a class="headerlink" href="#synopsis" title="Permalink to this headline">¶</a></h2>
<p><strong>bcfg2-crypt</strong> [-C <em>configfile</em>] [&#8211;decrypt|&#8211;encrypt]
[&#8211;cfg|&#8211;properties] [&#8211;stdout] [&#8211;remove] [&#8211;xpath <em>xpath</em>]
[-p <em>passphrase-or-name</em>] [-v] [-I] <em>filename</em> [<em>filename</em>...]</p>
<div class="section" id="description">
<h2>Description<a class="headerlink" href="#description" title="Permalink to this headline">¶</a></h2>
<p><strong class="program">bcfg2-crypt</strong> performs encryption and decryption of Cfg and
Properties files. It&#8217;s often sufficient to run <strong class="program">bcfg2-crypt</strong>
with only the name of the file you wish to encrypt or decrypt; it can
usually figure out what to do.</p>
<div class="section" id="options">
<h2>Options<a class="headerlink" href="#options" title="Permalink to this headline">¶</a></h2>
<table class="docutils option-list" frame="void" rules="none">
<col class="option" />
<col class="description" />
<tbody valign="top">
<tr><td class="option-group">
<kbd><span class="option">-C <var>configfile</var></span></kbd></td>
<td>Specify alternate bcfg2.conf location.</td></tr>
<tr><td class="option-group" colspan="2">
<kbd><span class="option">--decrypt</span>, <span class="option">--encrypt</span></kbd></td>
<tr><td>&nbsp;</td><td>Select encryption or decryption mode for the
given file(s). This is usually unnecessary, as
<strong class="program">bcfg2-crypt</strong> can often determine which
is necessary based on the contents of each file.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">--cfg</span></kbd></td>
<td>An XML file should be encrypted in its entirety
rather than element-by-element. This is only
necessary if the file is an XML file whose name
ends with <em>.xml</em> and whose top-level tag is
<em>&lt;Properties&gt;</em>. See [MODES] below for details.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">--properties</span></kbd></td>
<td>Process a file as an XML Properties file, and
encrypt the text of each element
separately. This is necessary if, for example,
you&#8217;ve used a different top-level tag than
<em>Properties</em> in your Properties files. See
[MODES] below for details.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">--stdout</span></kbd></td>
<td>Print the resulting file to stdout instead of
writing it to a file.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">--remove</span></kbd></td>
<td>Remove the plaintext file after it has been
encrypted.  Only meaningful for Cfg files.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">--xpath <var>xpath</var></span></kbd></td>
<td>Encrypt the character content of all elements
that match the specified XPath expression.  The
default is <em>*[&#64;encrypted]</em> or <em>*</em>; see [MODES]
below for more details. Only meaningful for
Properties files.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">-p <var>passphrase</var></span></kbd></td>
<td>Specify the name of a passphrase specified in
the <em>[encryption]</em> section of <em>bcfg2.conf</em>. See
[SELECTING PASSPHRASE] below for more details.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">-v</span></kbd></td>
<td>Be verbose.</td></tr>
<tr><td class="option-group">
<kbd><span class="option">-I</span></kbd></td>
<td>When encrypting a Properties file, interactively
select the elements whose data should be
<tr><td class="option-group">
<kbd><span class="option">-h</span></kbd></td>
<td>Print usage information.</td></tr>
<div class="section" id="modes">
<h2>Modes<a class="headerlink" href="#modes" title="Permalink to this headline">¶</a></h2>
<p><strong class="program">bcfg2-crypt</strong> can encrypt Cfg files or Properties files; they
are handled very differently.</p>
<dl class="docutils">
<dd>When <strong class="program">bcfg2-crypt</strong> is used on a Cfg file, the entire file
is encrypted. This is the default behavior on files that are not
XML, or that are XML but whose top-level tag is not <em>&lt;Properties&gt;</em>.
This can be enforced by use of the <em>&#8211;cfg</em> option.</dd>
<dd>When <strong class="program">bcfg2-crypt</strong> is used on a Properties file, it
encrypts the character content of elements matching the XPath
expression given by <em>&#8211;xpath</em>. By default the expression is
<em>*[&#64;encrypted]</em>, which matches all elements with an <em>encrypted</em>
attribute. If you are encrypting a file and that expression doesn&#8217;t
match any elements, then the default is <em>*</em>, which matches
everything. When <strong class="program">bcfg2-crypt</strong> encrypts the character
content of an element, it also adds the <em>encrypted</em> attribute, set
to the name of the passphrase used to encrypt that element. When it
decrypts an element it does not remove <em>encrypted</em>, though; this
lets you easily and efficiently run <strong class="program">bcfg2-crypt</strong> against a
single Properties file to encrypt and decrypt it without needing to
specify a long list of options. See the online Bcfg2 docs on
Properties files for more information on how this works.</dd>
<div class="section" id="selecting-passphrase">
<h2>Selecting passphrase<a class="headerlink" href="#selecting-passphrase" title="Permalink to this headline">¶</a></h2>
<p>The passphrase used to encrypt or decrypt a file is discovered in the
following order.</p>
<ol class="arabic simple">
<li>The passphrase given on the command line using <em>-p</em> is used.</li>
<li>If exactly one passphrase is specified in <em>bcfg2.conf</em>, it will be
<li>If operating in Properties mode, <em>bcfg2.conf</em> will attempt to read
the name of the passphrase from the encrypted elements.</li>
<li>If decrypting, all passphrases will be tried sequentially.</li>
<li>If no passphrase has been determined at this point, an error is
produced and the file being encrypted or decrypted is skipped.</li>
<div class="section" id="see-also">
<h2>See Also<a class="headerlink" href="#see-also" title="Permalink to this headline">¶</a></h2>
<p><em class="manpage">bcfg2-server(8)</em></p>

