diff --git a/website/source/docs/guides/generate-root.html.md b/website/source/docs/guides/generate-root.html.md index 259c4bf121..21279df4b7 100644 --- a/website/source/docs/guides/generate-root.html.md +++ b/website/source/docs/guides/generate-root.html.md @@ -1,12 +1,12 @@ --- layout: "docs" -page_title: "Generate Root" +page_title: "Generate Root Tokens Using Unseal Keys" sidebar_current: "docs-guides-generate-root" description: |- - Generate a new root key using a threshold of unseal keys. + Generate a new root token using a threshold of unseal keys. --- -# Generate a root token (when none exists) +# Generate Root Tokens Using Unseal Keys It's considered [best practice](../concepts/tokens.html#root-tokens) not to keep root tokens around, as they are all-powerful. Instead, if one is @@ -15,10 +15,10 @@ absolutely needed, create it using Vault's `generate-root` command: 1. Unseal the vault. You do not need to be authenticated (you do not need an existing root token). 2. Generate a one-time password with `vault generate-root -genotp`. -3. Get the encoded root token: `vault generate-root -otp ` +3. Get the encoded root token with `vault generate-root -otp `. (Requires a quorum of unseal keys again, so needs to be done \ times.) 4. Decode the encoded root token with -`vault generate-root -otp -decode= ` +`vault generate-root -otp -decode=`. See `vault generate-root -help` for information on the alternate technique using a PGP key.