/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to mandos.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-07-20 03:03:33 UTC
  • mto: (237.7.594 trunk)
  • mto: This revision was merged to the branch mainline in revision 325.
  • Revision ID: teddy@recompile.se-20150720030333-203m2aeblypcsfte
Bug fix for GnuTLS 3: be compatible with old 2048-bit DSA keys.

The mandos-keygen program in Mandos version 1.6.0 and older generated
2048-bit DSA keys, and when GnuTLS uses these it has trouble
connecting using the Mandos default priority string.  This was
previously fixed in Mandos 1.6.2, but the bug reappeared when using
GnuTLS 3, so the default priority string has to change again; this
time also the Mandos client has to change its default, so now the
server and the client should use the same default priority string:

SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA:+SIGN-DSA-SHA256

* mandos (main/server_defaults): Changed default priority string.
* mandos-options.xml (/section/para[id="priority_compat"]): Removed.
  (/section/para[id="priority"]): Changed default priority string.
* mandos.conf ([DEFAULT]/priority): - '' -
* mandos.conf.xml (OPTIONS/priority): Refer to the id "priority"
                                      instead of "priority_compat".
* mandos.xml (OPTIONS/--priority): - '' -
* plugins.d/mandos-client.c (main): Changed default priority string.

Show diffs side-by-side

added added

removed removed

Lines of Context:
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY COMMANDNAME "mandos">
5
 
<!ENTITY TIMESTAMP "2017-02-23">
 
5
<!ENTITY TIMESTAMP "2015-07-20">
6
6
<!ENTITY % common SYSTEM "common.ent">
7
7
%common;
8
8
]>
37
37
      <year>2011</year>
38
38
      <year>2012</year>
39
39
      <year>2013</year>
40
 
      <year>2014</year>
41
 
      <year>2015</year>
42
 
      <year>2016</year>
43
 
      <year>2017</year>
44
40
      <holder>Teddy Hogeborn</holder>
45
41
      <holder>Björn Påhlsson</holder>
46
42
    </copyright>
543
539
        </listitem>
544
540
      </varlistentry>
545
541
      <varlistentry>
 
542
        <term><filename class="devicefile">/dev/log</filename></term>
 
543
      </varlistentry>
 
544
      <varlistentry>
546
545
        <term><filename
547
546
        class="directory">/var/lib/mandos</filename></term>
548
547
        <listitem>
554
553
        </listitem>
555
554
      </varlistentry>
556
555
      <varlistentry>
557
 
        <term><filename class="devicefile">/dev/log</filename></term>
 
556
        <term><filename>/dev/log</filename></term>
558
557
        <listitem>
559
558
          <para>
560
559
            The Unix domain socket to where local syslog messages are
589
588
      This server does not check the expire time of clients’ OpenPGP
590
589
      keys.
591
590
    </para>
592
 
    <xi:include href="bugs.xml"/>
593
591
  </refsect1>
594
592
  
595
593
  <refsect1 id="example">
708
706
      </varlistentry>
709
707
      <varlistentry>
710
708
        <term>
711
 
          <ulink url="https://gnutls.org/">GnuTLS</ulink>
 
709
          <ulink url="http://gnutls.org/">GnuTLS</ulink>
712
710
        </term>
713
711
      <listitem>
714
712
        <para>