/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to INSTALL

  • Committer: Teddy Hogeborn
  • Date: 2015-03-10 18:52:09 UTC
  • mto: (237.7.304 trunk)
  • mto: This revision was merged to the branch mainline in revision 325.
  • Revision ID: teddy@recompile.se-20150310185209-lxuovbu09zwyk9bx
Automatically determine the number of DH bits in the TLS handshake.

Instead of using a default value of 1024, check the OpenPGP key and
determine an appropriate number of DH bits to use, (using GnuTLS
functions made for this).  Document this new default behavior.

* plugins.d/mandos-client.c (safe_string): New function.
  (init_gnutls_global): If not specified, determine the number of DH
                        bits to use, based on the OpenPGP key.
* plugins.d/mandos-client.xml (OPTIONS): Document this new default of
                                         the --dh-bits option.

Thanks to Andreas Fischer <af@bantuX.org> for reporting this issue.

Show diffs side-by-side

added added

removed removed

Lines of Context:
41
41
    + GnuTLS 2.4          http://www.gnutls.org/
42
42
      Note: GnuTLS 3 will only work with Python-GnuTLS 2
43
43
    + Avahi 0.6.16        http://www.avahi.org/
44
 
    + Python 2.6          https://www.python.org/
 
44
    + Python 2.7          https://www.python.org/
45
45
    + Python-GnuTLS 1.1.5 https://pypi.python.org/pypi/python-gnutls/
46
46
    + dbus-python 0.82.4  http://dbus.freedesktop.org/doc/dbus-python/
47
47
    + PyGObject 2.14.2    https://developer.gnome.org/pygobject/
48
48
    + pkg-config  http://www.freedesktop.org/wiki/Software/pkg-config/
49
 
    + Python-argparse     https://pypi.python.org/pypi/argparse
50
49
    + Urwid 1.0.1         http://urwid.org/
51
50
      (Only needed by the "mandos-monitor" tool.)
52
51
    
141
140
  If IPsec is not used and SSH is not installed, it is suggested that
142
141
  a more cryptographically secure checker program is used and
143
142
  configured, since, without IPsec, ping packets can be faked.
 
143
 
 
144
#+STARTUP: showall