File: barf.8.xml

package info (click to toggle)
libreswan 4.3-1%2Bdeb11u4
  • links: PTS, VCS
  • area: main
  • in suites: bullseye
  • size: 62,688 kB
  • sloc: ansic: 108,293; sh: 25,973; xml: 11,756; python: 10,230; makefile: 1,580; javascript: 1,353; yacc: 825; sed: 647; perl: 584; lex: 159; awk: 156
file content (115 lines) | stat: -rw-r--r-- 4,002 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.1.2//EN"
                   "http://www.oasis-open.org/docbook/xml/4.1.2/docbookx.dtd">
<!-- lifted from troff+man by doclifter -->
<refentry id='barf8'>
<refentryinfo>
  <author><firstname>Paul</firstname><surname>Wouters</surname><authorblurb><para>placeholder to suppress warning</para> </authorblurb></author>
</refentryinfo>
<refmeta>
<refentrytitle>IPSEC_BARF</refentrytitle>
<manvolnum>8</manvolnum>
<refmiscinfo class='date'>4 September 2016</refmiscinfo>
<refmiscinfo class="source">libreswan</refmiscinfo>
<refmiscinfo class="manual">Executable programs</refmiscinfo>
</refmeta>
<refnamediv id='name'>
<refname>ipsec barf</refname>
<refpurpose>spew out collected IPsec debugging information</refpurpose>
</refnamediv>
<!-- body begins here -->
<refsynopsisdiv id='synopsis'>
<cmdsynopsis>
  <command>ipsec</command>
    <arg choice='plain'><replaceable>barf</replaceable></arg>
    <arg choice='opt'><arg choice='plain'>--short</arg></arg>
</cmdsynopsis>
</refsynopsisdiv>


<refsect1 id='description'><title>DESCRIPTION</title>
<para><emphasis remap='I'>Barf</emphasis>
outputs (on standard output) a collection of debugging information
(contents of files, selections from logs, etc.)
related to the IPsec encryption/authentication system.
It is primarily a convenience for remote debugging,
a single command that packages up (and labels) all information
that might be relevant to diagnosing a problem in IPsec.</para>


<para>The
<option>--short</option>
option limits the length of
the log portion of
<emphasis remap='I'>barf</emphasis>'s
output, which can otherwise be extremely voluminous
if debug logging is turned on.</para>

<para>On systems with systemd, ipsec barf will look for logs
using the journalctl command. If the logfile= option is used,
logs will also not be found by the ipsec barf command.</para>

<para><emphasis remap='I'>Barf</emphasis>
censors its output,
replacing keys
and secrets with brief checksums to avoid revealing sensitive information.</para>

<para>Beware that the output of both commands is aimed at humans,
not programs,
and the output format is subject to change without warning.</para>

<para><emphasis remap='I'>Barf</emphasis>
has to figure out which files in
<filename>/var/log</filename>
contain the IPsec log messages.
It looks for general log messages first in
<emphasis remap='I'>messages</emphasis>
and
<emphasis remap='I'>syslog</emphasis>,
and for Pluto messages first in
<emphasis remap='I'>secure</emphasis>,
<emphasis remap='I'>auth.log</emphasis>,
and
<emphasis remap='I'>debug</emphasis>.
In both cases,
if it does not find what it is looking for in one of those &ldquo;likely&rdquo; places,
it will resort to a brute-force search of most (non-compressed) files in
<filename>/var/log</filename>.</para>
</refsect1>

<refsect1 id='files'><title>FILES</title>
<literallayout remap='.nf'>
/proc/net/*
/var/log/*
/etc/ipsec.conf
@IPSEC_SECRETS_FILE@
</literallayout> <!-- .fi -->
</refsect1>

<refsect1 id='history'><title>HISTORY</title>
<para>Written for the Linux FreeS/WAN project
&lt;<ulink url='https://www.freeswan.org'>https://www.freeswan.org</ulink>&gt;
by Henry Spencer.</para>
</refsect1>

<refsect1 id='bugs'><title>BUGS</title>
<para><emphasis remap='I'>Barf</emphasis>
uses heuristics to try to pick relevant material out of the logs,
and relevant messages
that are not labelled with any of the tags that
<emphasis remap='I'>barf</emphasis>
looks for will be lost.
We think we've eliminated the last such case, but one never knows...</para>

<para>Finding
<emphasis remap='I'>updown</emphasis>
scripts (so they can be included in output) is, in general, difficult.
<emphasis remap='I'>Barf</emphasis>
uses a very simple heuristic that is easily fooled.</para>

<para>The brute-force search for the right log files can get expensive on
systems with a lot of clutter in
<filename>/var/log</filename>.</para>
</refsect1>
</refentry>