8
8
** [#B] Seperate more code to function for more readability
9
9
** [#A] Man page: man8/plugin-runner.8mandos
12
Environment is modified according to options and passed to plugins
12
14
Examples of normal usage, debug usage, debugging single or all
18
Note the danger of using this program, since you might lock
19
yourself out of your system without any means of entering the root
20
file system password. This is, however, very unlikely considering
21
the fallback to getpass(3).
18
24
Explaining text on what you can read
19
** Keydir move: /etc/mandos -> /etc/keys/mandos
20
Must create in preinst if not pre-depending on cryptsetup
23
27
** [#A] Man page: man8/password-request.8mandos
51
55
** Do not depend on GnuPG key rings on disk
52
56
This would mean creating new GnuPG key rings with GPGME by
53
57
importing the key files from scratch on every program start.
58
** Keydir move: /etc/mandos -> /etc/keys/mandos
59
Must create in preinst if not pre-depending on cryptsetup
56
** [#A] Man page: man8/password-prompt.8mandos
58
Document short options
60
Note that this is more or less a simple getpass(3) wrapper, even
61
though actual use of getpass(3) is not guaranteed.
64
Document use of "cryptsource" and "crypttarget".
68
Examples of normal usage, debug usage, with a prefix, etc.
70
Not much to do here but it is noteworthy to state the danger of
71
not having a fallback option.
73
Refer to mandos-client(8mandos) and password-request(8mandos)
74
and also, perhaps, to cryptsetup(8)?
62
** [#C] Use getpass(3)?
76
63
Man page says "obsolete", but [[info:libc:getpass][GNU LibC Manual: Reading Passwords]]
77
64
does not. See also [[http://sources.redhat.com/ml/libc-alpha/2003-05/msg00251.html][Marcus Brinkmann: Re: getpass obsolete?]] and
78
65
[[http://article.gmane.org/gmane.comp.lib.glibc.alpha/4906][Petter Reinholdtsen: Re: getpass obsolete?]], and especially also
79
66
[[http://www.steve.org.uk/Reference/Unix/faq_4.html#SEC48][Unix Programming FAQ 3.1 How can I make my program not echo input?]]
82
** [#A] Config file man page: man5/mandos.conf (mandos.conf)
83
** [#A] Config file man page: man5/mandos-clients.conf (clients.conf)
84
69
** [#A] /etc/init.d/mandos-server :teddy:
85
70
** [#B] Log level :bugs:
86
71
** /etc/mandos/clients.d/*.conf
91
** Use xinclude for common sections
107
97
*** Update initrd.img after installation
108
98
This seems to use some kind of "trigger" system
99
[[file:/usr/share/doc/dpkg/triggers.txt.gz]]
100
dpkg-trigger(1), deb-triggers(5)
101
*** Keydir move: /etc/mandos -> /etc/keys/mandos
102
Must create in preinst if not pre-depending on cryptsetup
104
**** "--passfile" option
105
Using the "secfile" option instead of "secret"
106
**** [#A] "--test" option
107
For testing decryption before rebooting.
110
109
*** [#A] Create mandos user and group for server
111
110
*** [#A] Create /var/run/mandos directory with perm and ownership
114
*** [#A] Output cut-and-paste ready snippet for clients.conf.
117
113
** /usr/share/initramfs-tools/hooks/mandos
118
114
*** Do not install in initrd.img if configured not to.
119
115
Use "/etc/initramfs-tools/conf.d/mandos"? Definitely a debconf
121
117
** /etc/bash_completion.d/mandos
122
*** From XML sources directly?
118
From XML sources directly?