+@node How to configure, , Host configuration variables, Configuration file
+@subsection How to configure
+
+@subsubheading Step 1. Creating the key files
+
+For each host, you have to create a pair of RSA keys. One key is your
+private key, which is only known to you. The other one is the public
+key, which you should copy to all hosts wanting to authenticate to you.
+
+
+@subsubheading Step 2. Configuring each host
+
+For every host in the VPN, you have to create two files. First there is
+the main configuration file, @file{/etc/tinc/vpn-name/tinc.conf}. In
+this file there should at least be three directives:
+
+@table @samp
+@item Name
+You should fill in the name of this host (or rather, the name of this
+leaf of the VPN). It can be called after the hostname, the physical
+location, the department, or the name of one of your boss' pets. It can
+be anything, as long as all these names are unique across the entire
+VPN.
+
+@item PrivateKey
+Fill in the full pathname to the file that contains the private RSA key.
+
+@item ConnectTo
+This is the name of the host that you want to connect to (not a DNS
+name, rather the name that is given with the Name parameter in that
+hosts tinc.conf). This is the upstream connection. If your computer is
+a central node, you might want to leave this out to make it stay idle
+until someone connects to it.
+@end table
+
+@cindex host configuration file
+Then you should create a file with the name you gave yourself in
+tinc.conf (the `Name' parameter), located in
+@file{/etc/tinc/vpn-name/hosts/}. In this file, which we call the
+`@emph{host configuration file}', only one variable is required:
+
+@table @samp
+@item Subnet
+The IP range that this host accepts as being `local'. All packets with
+a destination address that is within this subnet will be sent to us.
+@end table
+
+
+@subsubheading Step 3. Bringing it all together
+
+Now for all hosts that you want to create a direct connection to, -- you
+connect to them or they connect to you -- you get a copy of their host
+configuration file and their public RSA key.
+
+For each host configuration file, you add two variables:
+
+@table @samp
+@item Address
+Enter the IP address or DNS hostname for this host. This is only needed
+if you connect to this host.
+
+@item PublicKey
+Put the full pathname to this hosts public RSA key here.
+@end table
+
+When you did this, you should be ready to create your first connection.
+Pay attention to the system log, most errors will only be visible
+there. If you get an error, you can check @ref{Error messages}.
+
+
+@c ==================================================================
+@node Example, , Required directives, Configuring tinc