'\" t
.\" Title: useradd
.\" Author: Aurelien Requiem
.\" Generator: DocBook XSL Stylesheets v1.78.1
.\" Date: 11/18/2015
.\" Manual: System Management Commands
.\" Source: shadow-utils 4.2
.\" Language: English
.\"
.TH "DNSCRYPT-WRAPPER" "8" "December 26th, 2016" "Debian GNU/Linux" "Admin Manual"
.\" -----------------------------------------------------------------
.\" * Define some portability stuff
.\" -----------------------------------------------------------------
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.\" http://bugs.debian.org/507673
.\" http://lists.gnu.org/archive/html/groff/2009-02/msg00013.html
.\" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
.ie \n(.g .ds Aq \(aq
.el .ds Aq '
.\" -----------------------------------------------------------------
.\" * set default formatting
.\" -----------------------------------------------------------------
.\" disable hyphenation
.nh
.\" disable justification (adjust text to left margin only)
.ad l
.\" -----------------------------------------------------------------
.\" * MAIN CONTENT STARTS HERE *
.\" -----------------------------------------------------------------
.SH "NAME"
dnscrypt\-wrapper \- Creates an empty website template almost ready for deployment.
.SH SYNOPSIS
.B dnscrypt\-wrapper
.RB [\| \-h \|]
.RB [\| \-a
.IR \|]
.RB [\| \-r
.IR \|]
.RB [\| \-U \|]
.RB [\| \-u
.IR \|]
.RB [\| \-l
.IR \|]
.RB [\| \-p
.IR \|]
.RB [\| \-d \|]
.RB [\| \-V \|]
.RB [\| \-v \|]
.RB [\| \-\-gen-cert-file \|]
.RB [\| \-\-gen-crypt-keypair \|]
.RB [\| \-\-gen-provider-keypair \|]
.RB [\| \-\-show-provider-publickey-fingerprint \|]
.RB\fB [\| \-\-provider-cert-file=\fR\&\fI\fR \|]
.RB\fB [\| \-\-provider-name=\fR\&\fI\fR \|]
.RB\fB [\| \-\-provider-publickey-file=\fR\&\fI\fR \|]
.RB\fB [\| \-\-provider-secretkey-file=\fR\&\fI\fR \|]
.RB\fB [\| \-\-crypt-secretkey-file=\fR\&\fI\fR \|]
.RB\fB [\| \-\-cert-file-expire-days=\fR\&\fI\fR \|]
.SH DESCRIPTION
.BR dnscrypt\-wrapper
DNSCrypt is a protocol that authenticates communications between a DNS client and a DNS resolver. It prevents DNS spoofing. It uses cryptographic signatures to verify that responses originate from the chosen DNS resolver and haven't been tampered with.
.SH OPTIONS
.TP
\fB\-h\fR, \fB\--help\fR,
.RS 4
Display dnscrypt\-wrapper help message and exit.
.RE
.TP
\fB\-a\fR\ \&\fI\fR, \fB\-\-listen-address=\fR\&\fI\fR
.RS 4
Set local address to listen (default: 0.0.0.0:53).
.RE
.TP
\fB\fR\ \&\fI\-r\fR, \fB\-\-resolver\-address=\fR\&\fI\fR
.RS 4
Set the upstream dns resolver server ().
.RE
.TP
\fB\-U\fR, \fB\-\-unauthenticated\fR
.RS 4
Allow and forward unauthenticated queries (default: off).
.RE
.TP
\fB\-u\fR\ \&\fI\fR, \fB\-\-user=\fR\&\fI\fR
.RS 4
Run the service as given user.
.RE
.TP
\fB\-l\fR\ \&\fI\fR, \fB\-\-logfile=\fR\&\fI\fR
.RS 4
Logs file path (default: stdout).
.RE
.TP
\fB\-p\fR\ \&\fI\fR, \fB\-\-pidfile=\fR\&\fI\fR
.RS 4
Pid file path (default: none).
.RE
.TP
\fB\-d\fR, \fB\-\-daemonize\fR
.RS 4
Run as daemon (default: off).
.RE
.TP
\fB\-V\fR, \fB\-\-verbose\fR
.RS 4
Set the service to be more verbose. Specify more \-VVV to increase verbosity.
.RE
.TP
\fB\-v\fR, \fB\-\-version\fR
.RS 4
Show version info and exit.
.RE
.TP
\fB\-\-gen\-cert\-file\fR
.RS 4
Generate pre\-signed certificate
.RE
.TP
\fB\-\-gen\-crypt\-keypair\fR
.RS 4
Generate crypt key pair
.RE
.TP
\fB\-\-gen\-provider\-keypair\fR
.RS 4
Generate provider key pair
.RE
.TP
\fB\-\-show\-provider\-publickey\-fingerprint\fR
.RS 4
Display provider public key fingerprint
.RE
.TP
\fB\-\-provider\-cert\-file=\fR\&\fI\fR
.RS 4
Certificate file (default: ./dnscrypt.cert)
.RE
.TP
\fB\-\-provider\-name=\fR\&\fI\fR
.RS 4
Provider name.
.RE
.TP
\fB\-\-provider\-publickey\-file=\fR\&\fI\fR
.RS 4
Provider public key file (default: ./public.key).
.RE
.TP
\fB\-\-provider\-secretkey\-file=\fR\&\fI\fR
.RS 4
Provider secret key file (default: ./secret.key).
.RE
.TP
\fB\-\-crypt\-secretkey\-file=\fR\&\fI\fR
.RS 4
Crypt secret key file (default: ./crypt_secret.key).
.RE
.TP
\fB\-\-cert\-file\-expire\-days=\fR\&\fI\fR
.RS 4
cert file expire days (default: 365).
.PP
.
.SH "SEE ALSO"
\fBdnscrypt-proxy\fR(8)