--- /dev/null
+install -d -m 700 \
+ "$tool"/var/sec \
+ "$tool"/var/sec/"$site"
+if test ! -e "$tool"/var/sec/"$site"/encryption_key.gpg
+ then gpg --encrypt $gpg_options -o "$tool"/var/sec/"$site"/encryption_key.gpg <<-EOF
+ $(stdbuf --output 0 tr -d -c '[:alnum:]' <"${random:-/dev/urandom}" | head -c 42)
+ EOF
+ fi
+
+cat "$tool"/etc/"$site"/config.php - <<-EOF |
+ \$config['encryption_key'] = '$(gpg --decrypt "$tool"/var/sec/"$site"/encryption_key.gpg)';
+ EOF
+"$tool"/remote/ssh root@"$local_fqdn" ' \
+ set -efux
+ sudo install -d -m 750 -o root -g root \
+ /etc/'"$site"'
+ sudo install -m 640 -o root -g root /dev/stdin \
+ /etc/'"$site"'/config.php
+ '