/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to mandos-clients.conf.xml

Merge "--socket" option for server.

This is suggested by the GNU Coding Standards' Table of Long Options,
and will probably also allow socket activation (e.g. by systemd(8)).

Show diffs side-by-side

added added

removed removed

Lines of Context:
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY CONFNAME "mandos-clients.conf">
5
5
<!ENTITY CONFPATH "<filename>/etc/mandos/clients.conf</filename>">
6
 
<!ENTITY TIMESTAMP "2016-03-05">
 
6
<!ENTITY TIMESTAMP "2012-05-27">
7
7
<!ENTITY % common SYSTEM "common.ent">
8
8
%common;
9
9
]>
37
37
      <year>2010</year>
38
38
      <year>2011</year>
39
39
      <year>2012</year>
40
 
      <year>2013</year>
41
 
      <year>2014</year>
42
 
      <year>2015</year>
43
 
      <year>2016</year>
44
40
      <holder>Teddy Hogeborn</holder>
45
41
      <holder>Björn Påhlsson</holder>
46
42
    </copyright>
121
117
          <para>
122
118
            How long to wait for external approval before resorting to
123
119
            use the <option>approved_by_default</option> value.  The
124
 
            default is <quote>PT0S</quote>, i.e. not to wait.
 
120
            default is <quote>0s</quote>, i.e. not to wait.
125
121
          </para>
126
122
          <para>
127
123
            The format of <replaceable>TIME</replaceable> is the same
181
177
            <varname>PATH</varname> will be searched.  The default
182
178
            value for the checker command is <quote><literal
183
179
            ><command>fping</command> <option>-q</option> <option
184
 
            >--</option> %%(host)s</literal></quote>.  Note that
185
 
            <command>mandos-keygen</command>, when generating output
186
 
            to be inserted into this file, normally looks for an SSH
187
 
            server on the Mandos client, and, if it find one, outputs
188
 
            a <option>checker</option> option to check for the
189
 
            client’s key fingerprint – this is more secure against
190
 
            spoofing.
 
180
            >--</option> %%(host)s</literal></quote>.
191
181
          </para>
192
182
          <para>
193
183
            In addition to normal start time expansion, this option
345
335
            <option>extended_timeout</option> option.
346
336
          </para>
347
337
          <para>
348
 
            The <replaceable>TIME</replaceable> is specified as an RFC
349
 
            3339 duration; for example
350
 
            <quote><literal>P1Y2M3DT4H5M6S</literal></quote> meaning
351
 
            one year, two months, three days, four hours, five
352
 
            minutes, and six seconds.  Some values can be omitted, see
353
 
            RFC 3339 Appendix A for details.
 
338
            The <replaceable>TIME</replaceable> is specified as a
 
339
            space-separated number of values, each of which is a
 
340
            number and a one-character suffix.  The suffix must be one
 
341
            of <quote>d</quote>, <quote>s</quote>, <quote>m</quote>,
 
342
            <quote>h</quote>, and <quote>w</quote> for days, seconds,
 
343
            minutes, hours, and weeks, respectively.  The values are
 
344
            added together to give the total time value, so all of
 
345
            <quote><literal>330s</literal></quote>,
 
346
            <quote><literal>110s 110s 110s</literal></quote>, and
 
347
            <quote><literal>5m 30s</literal></quote> will give a value
 
348
            of five minutes and thirty seconds.
354
349
          </para>
355
350
        </listitem>
356
351
      </varlistentry>
463
458
      <literal>%(<replaceable>foo</replaceable>)s</literal> is
464
459
      obscure.
465
460
    </para>
466
 
    <xi:include href="bugs.xml"/>
467
461
  </refsect1>
468
462
  
469
463
  <refsect1 id="example">
471
465
    <informalexample>
472
466
      <programlisting>
473
467
[DEFAULT]
474
 
timeout = PT5M
475
 
interval = PT2M
 
468
timeout = 5m
 
469
interval = 2m
476
470
checker = fping -q -- %%(host)s
477
471
 
478
472
# Client "foo"
495
489
        4T2zw4dxS5NswXWU0sVEXxjs6PYxuIiCTL7vdpx8QjBkrPWDrAbcMyBr2O
496
490
        QlnHIvPzEArRQLo=
497
491
host = foo.example.org
498
 
interval = PT1M
 
492
interval = 1m
499
493
 
500
494
# Client "bar"
501
495
[bar]
502
496
fingerprint = 3e393aeaefb84c7e89e2f547b3a107558fca3a27
503
497
secfile = /etc/mandos/bar-secret
504
 
timeout = PT15M
 
498
timeout = 15m
505
499
approved_by_default = False
506
 
approval_delay = PT30S
 
500
approval_delay = 30s
507
501
      </programlisting>
508
502
    </informalexample>
509
503
  </refsect1>
522
516
      <citerefentry><refentrytitle>fping</refentrytitle>
523
517
      <manvolnum>8</manvolnum></citerefentry>
524
518
    </para>
525
 
    <variablelist>
526
 
      <varlistentry>
527
 
        <term>
528
 
          RFC 3339: <citetitle>Date and Time on the Internet:
529
 
          Timestamps</citetitle>
530
 
        </term>
531
 
      <listitem>
532
 
        <para>
533
 
          The time intervals are in the "duration" format, as
534
 
          specified in ABNF in Appendix A of RFC 3339.
535
 
        </para>
536
 
      </listitem>
537
 
      </varlistentry>
538
 
    </variablelist>
539
519
  </refsect1>
540
520
</refentry>
541
521
<!-- Local Variables: -->