2
configuration for OpenPGP key dir
3
header files/symbols tally
4
check exit codes of all system calls
6
protocol version header
7
use strsep instead of strtok?
10
header files/symbols tally
11
check exit codes of all system calls
12
change uid to nobody:nogroup
13
other drop privs stuff?
14
pass things in environment, like device name, etc
15
Does cryptsetup already do this?
16
use strsep instead of strtok?
21
protocol version header
22
Run-time communication with server
25
[Mandos-tools/utilities]
4
** TODO [#B] use scandir(3) instead of readdir(3)
5
** TODO [#B] Prefix all debug output with argv[0]
6
** TODO [#B] Retry a server which has a non-definite reply:
7
*** A closed connection during the TLS handshake
9
** TODO [#B] Use capabilities instead of seteuid().
12
** TODO [#B] use scandir(3) instead of readdir(3)
13
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
16
** TODO [#B] use scandir(3) instead of readdir(3)
17
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
20
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
21
** TODO [#B] Drop privileges after opening FIFO.
24
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
29
** TODO [#B] use scandir(3) instead of readdir(3)
30
** TODO [#C] use same file name rules as run-parts(8)
33
** TODO [#B] Log level :BUGS:
34
** TODO /etc/mandos/clients.d/*.conf
35
Watch this directory and add/remove/update clients?
36
** TODO config for TXT record
37
** TODO [#B] Run-time communication with server :BUGS:
42
syslogger.setLevel(logging.WARNING)
43
+ [[http://log.ometer.com/2007-05.html][Best D-Bus practices]]
44
** TODO Implement --foreground :BUGS:
45
[[info:standards:Option%20Table][Table of Long Options]]
46
** TODO Implement --socket
47
[[info:standards:Option%20Table][Table of Long Options]]
48
** TODO Date+time on console log messages :BUGS:
50
** TODO DBusServiceObjectUsingSuper
51
** TODO Global enable/disable flag
52
** TODO By-client countdown on secrets given
53
** TODO Fix problem with fsck taking a really long time
54
Whenever a client successfully gets a secret it could get a
55
one-time timeout boost to allow for an fsck-incurred delay
56
** TODO Delay before client receives key
57
This would give an operator opportunity to cancel the request if
59
** TODO Client manual approval mode
60
A client needs manual approval on the server before it gets the
62
** TODO Persistent state
66
** [[file:mandos.xml::XXX][Document D-Bus interface]]
68
* Provide and install /etc/dbus-1/system.d/mandos.conf
71
*** Handle "no D-Bus server" and/or "no Mandos server found" better
72
*** [#B] --dump option
74
* TODO mandos-dispatch
75
Listens for specified D-Bus signals and spawns shell commands with
79
** D-Bus main loop w/ signal receiver
80
** Urwid client data displayer
86
** TODO Loop until passwords match when run interactively
87
** TODO "--secfile" option
88
Using the "secfile" option instead of "secret"
89
** TODO [#B] "--test" option
90
For testing decryption before rebooting.
93
** Implement DEB_BUILD_OPTIONS
94
http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
97
** /usr/share/initramfs-tools/hooks/mandos
98
*** TODO [#C] use same file name rules as run-parts(8)
99
*** TODO [#C] Do not install in initrd.img if configured not to.
100
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
101
** TODO [#C] /etc/bash_completion.d/mandos
102
From XML sources directly?