Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ image:https://img.shields.io/badge/module-github.com%2Frtbrick%2Ftools-green.svg
| Tool | Description

| `rtb-buddy`
| Multipurpose helper tool for the RtBrick fullstack. See link:cmd/rtb-buddy/README.adoc[documentation].
| Multipurpose tool for the RtBrick Full Stack Network Operating System. See link:cmd/rtb-buddy/README.adoc[rtb-buddy documentation] for details.

|===

Expand Down
20 changes: 10 additions & 10 deletions cmd/rtb-buddy/README.adoc
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
= rtb-buddy

Multipurpose helper tool for the RtBrick fullstack.
Multipurpose tool for the RtBrick Full Stack Network Operating System (RBFS).

== Installation

Expand Down Expand Up @@ -60,11 +60,11 @@ source <(rtb-buddy completion bash)

=== apigwd

APIGWD relevant commands.
APIGWD related commands.

==== apigw generate jwks

Generate an RSA key pair as two JWKS files.
Generates an RSA key pair as two JWKS files.

* `--priv` — output path for the private JWKS (default: `apigw-jwks-priv.json`)
* `--pub` — output path for the public JWKS (default: `apigw-jwks.json`)
Expand All @@ -79,9 +79,9 @@ rtb-buddy apigw generate jwks
rtb-buddy apigw generate jwks --kid "prod" --priv prod-jwks-priv.json --pub prod-jwks.json
----

=== apigw generate token
==== apigw generate token

Generate a signed JWT. The private key is read from the JWKS file.
Generates a signed JWT. The private key is read from the JWKS file.

* `--priv` — private JWKS file path (default: `apigw-jwks-priv.json`)
* `--kid` — key ID to select from the JWKS (empty = first key)
Expand Down Expand Up @@ -147,13 +147,13 @@ LI X1 mTLS certificate management commands for Lawful Intercept.

==== mTLS Setup

LI X1 uses mutual TLS (mTLS) between ADMF (Administrative Function / management system) and RBFS (network device).
LI X1 uses mutual TLS (mTLS) between ADMF (Administrative Function, the LI management system) and RBFS (network element, the network device).

CA:: Trust anchor — issues certificates for all components
RBFS:: Server — presents certificate, verifies ADMF clients
ADMF:: Client — presents certificate, verifies RBFS server

===== Generate certificates
===== Generating the CA and certificates

[source,sh]
----
Expand All @@ -176,7 +176,7 @@ Both sides need `ca.crt` to verify each other's certificates.

==== lix1 generate ca

Generate a root CA certificate and private key.
Generates a root CA certificate and private key.

* `--ca-crt` — CA certificate output path (default: `ca.crt`)
* `--ca-crt-key` — CA private key output path (default: `ca.key`)
Expand All @@ -193,7 +193,7 @@ rtb-buddy lix1 generate ca --cn "My CA" --org "My Org" --ou "Eng" --ca-crt my-ca

==== lix1 generate cert

Generate a certificate signed by the CA.
Generates a certificate signed by the CA.

* `--ca-crt` — CA certificate input path (default: `ca.crt`)
* `--ca-crt-key` — CA private key input path (default: `ca.key`)
Expand All @@ -213,7 +213,7 @@ rtb-buddy lix1 generate cert --cn "RBFS" --org "RtBrick" --ou "Engineering" --cr

==== lix1 test cert

Test certificate validity and chain verification.
Validates the certificate and it's trust chain.

* `--crt` — Certificate to test (required)
* `--ca-crt` — CA certificate for chain validation (default: `ca.crt`)
Expand Down
Loading