/testing/guestbin/swan-prep --nokeys --fips
Creating empty NSS database
Password changed successfully.
FIPS mode enabled.
west #
 ipsec newhostkey
Generated RSA key pair with CKAID <<CKAID#1>> was stored in the NSS database
The public key can be displayed using: ipsec showhostkey --left --ckaid <<CKAID#1>>
west #
 ipsec showhostkey --list
< 1> RSA keyid: <<KEYID#1>> ckaid: <<CKAID#1>>
west #
 ckaid=$(ipsec showhostkey --list | sed -e 's/.*ckaid: //')
west #
 ipsec showhostkey --left --ckaid "$ckaid"
	# rsakey <<KEYID#1>>
	leftrsasigkey=0s<<RAW-PUBKEY#1>>
west #
 

