--- /dev/null
+install -d -m 700 \
+ "$tool"/var/sec \
+ "$tool"/var/sec/"$site"
+if test ! -e "$tool"/var/sec/"$site"/admin.pass.gpg
+ then gpg --encrypt $gpg_options -o "$tool"/var/sec/"$site"/admin.pass.gpg <<-EOF
+ $(stdbuf --output 0 tr -d -c '[:alnum:]' <"${random:-/dev/urandom}" | head -c 22)
+ EOF
+ fi
+
+gpg --decrypt ${gpg_options-} "$tool"/var/sec/"$site"/admin.pass.gpg |
+"$tool"/remote/ssh root@"$local_fqdn" '
+ set -eux
+ test ! -e /root/.'"$site"'_pass
+ install -m 400 -o root -g root /dev/stdin \
+ /root/.'"$site"'_pass
+ '