2
configuration for OpenPGP key dir
3
header files/symbols tally
4
check exit codes of all system calls
6
protocol version header
7
use strsep instead of strtok?
10
disable certain plugins
11
header files/symbols tally
12
check exit codes of all system calls
13
change uid to nobody:nogroup
14
other drop privs stuff?
15
pass things in environment, like device name, etc
16
Does cryptsetup already do this?
17
Configurable plugin dir
18
use strsep instead of strtok?
23
protocol version header
24
Run-time communication with server
27
[Mandos-tools/utilities]
3
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]]
8
** TODO [#B] Use capabilities instead of seteuid().
9
** TODO [#B] Use struct sockaddr_storage instead of a union
10
** TODO [#B] Use getaddrinfo(hints=AI_NUMERICHOST) instead of inet_pton()
11
** TODO [#B] Use getnameinfo(serv=NULL, NI_NUMERICHOST) instead of inet_ntop()
12
** TODO [#B] Prefer /run/tmp over /tmp, if it exists
15
** TODO [#B] use scandir(3) instead of readdir(3)
17
* usplash (Deprecated)
18
** TODO [#A] Make it work again
19
** TODO [#B] use scandir(3) instead of readdir(3)
22
** TODO [#B] Drop privileges after opening FIFO.
25
** TODO [#B] lock stdin (with flock()?)
32
** TODO handle printing for errors for plugins
33
*** Hook up stderr of plugins, buffer them, and prepend mandos pluig [plugin name]
34
** TODO [#B] use scandir(3) instead of readdir(3)
35
** TODO [#C] use same file name rules as run-parts(8)
36
** kernel command line option for debug info
37
** TODO [#B] Use openat()
40
** TODO [#B] Log level :BUGS:
41
*** TODO /etc/mandos/clients.d/*.conf
42
Watch this directory and add/remove/update clients?
43
** TODO [#C] config for TXT record
44
** TODO Log level dbus option
45
SetLogLevel D-Bus call
46
** TODO Implement --foreground :BUGS:
47
[[info:standards:Option%20Table][Table of Long Options]]
48
** TODO [#C] DBusServiceObjectUsingSuper
49
** TODO [#B] Global enable/disable flag
50
** TODO [#B] By-client countdown on number of secrets given
51
** TODO [#B] Support RFC 3339 time duration syntax
52
** D-Bus Client method NeedsPassword(50) - Timeout, default disapprove
53
+ SetPass(u"gazonk", True) -> Approval, persistent
54
+ Approve(False) -> Close client connection immediately
55
** TODO [#C] python-parsedatetime
56
** TODO [#C] systemd/launchd
57
http://0pointer.de/blog/projects/systemd.html
58
http://wiki.debian.org/systemd
59
** TODO Separate logging logic to own object
60
** TODO [#A] Limit approval_delay to max gnutls/tls timeout value
61
** TODO [#B] break the wait on approval_delay if connection dies
62
** TODO Generate Client.runtime_expansions from client options + extra
63
** TODO Allow %%(checker)s as a runtime expansion
64
** TODO Use python-tlslite?
65
** TODO D-Bus AddClient() method on server object
66
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods.
67
** TODO Emit [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-properties][org.freedesktop.DBus.Properties.PropertiesChanged]] signal
68
TODO Deprecate se.recompile.Mandos.Client.PropertyChanged - annotate!
69
TODO Can use "invalidates" annotation to also emit on changed secret.
70
** TODO Support [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-objectmanager][org.freedesktop.DBus.ObjectManager]] interface on server object
71
Deprecate methods GetAllClients(), GetAllClientsWithProperties()
72
and signals ClientAdded and ClientRemoved.
73
** TODO Save state periodically to recover better from hard shutdowns
74
** TODO CheckerCompleted method, deprecate CheckedOK
75
** TODO Secret Service API?
76
http://standards.freedesktop.org/secret-service/
79
** Add mandos contact info in manual pages
82
*** Handle "no D-Bus server" and/or "no Mandos server found" better
83
*** [#B] --dump option
84
** TODO Support RFC 3339 time duration syntax
86
* TODO mandos-dispatch
87
Listens for specified D-Bus signals and spawns shell commands with
91
** TODO help should be toggleable
92
** Urwid client data displayer
93
Better view of client data in the listing
95
** Print a nice "We are sorry" message, save stack trace to log.
96
** Show timeout countdown for approval
99
** TODO "--secfile" option
100
Using the "secfile" option instead of "secret"
101
** TODO [#B] "--test" option
102
For testing decryption before rebooting.
105
** TODO [#C] Implement DEB_BUILD_OPTIONS
106
http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
109
** /usr/share/initramfs-tools/hooks/mandos
110
*** TODO [#C] use same file name rules as run-parts(8)
111
*** TODO [#C] Do not install in initrd.img if configured not to.
112
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
113
** TODO [#C] /etc/bash_completion.d/mandos
114
From XML sources directly?
117
** TODO Locate which package moves the other bin/sh when busybox is deactivated
118
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox