/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to plugins.d/password-prompt.xml

  • Committer: Teddy Hogeborn
  • Date: 2017-08-20 14:14:14 UTC
  • mto: (237.7.594 trunk)
  • mto: This revision was merged to the branch mainline in revision 360.
  • Revision ID: teddy@recompile.se-20170820141414-m034xuebg7ccaeui
Add some more restrictions to the systemd service file.

* mandos.service ([Service]/ProtectKernelTunables): New; set to "yes".
  ([Service]/ProtectControlGroups): - '' -

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY COMMANDNAME "password-prompt">
6
 
<!ENTITY TIMESTAMP "2008-08-29">
 
5
<!ENTITY TIMESTAMP "2017-02-23">
 
6
<!ENTITY % common SYSTEM "../common.ent">
 
7
%common;
7
8
]>
8
9
 
9
 
<refentry>
 
10
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
10
11
  <refentryinfo>
11
12
    <title>Mandos Manual</title>
12
13
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
13
14
    <productname>Mandos</productname>
14
 
    <productnumber>&VERSION;</productnumber>
 
15
    <productnumber>&version;</productnumber>
15
16
    <date>&TIMESTAMP;</date>
16
17
    <authorgroup>
17
18
      <author>
18
19
        <firstname>Björn</firstname>
19
20
        <surname>Påhlsson</surname>
20
21
        <address>
21
 
          <email>belorn@fukt.bsnet.se</email>
 
22
          <email>belorn@recompile.se</email>
22
23
        </address>
23
24
      </author>
24
25
      <author>
25
26
        <firstname>Teddy</firstname>
26
27
        <surname>Hogeborn</surname>
27
28
        <address>
28
 
          <email>teddy@fukt.bsnet.se</email>
 
29
          <email>teddy@recompile.se</email>
29
30
        </address>
30
31
      </author>
31
32
    </authorgroup>
32
33
    <copyright>
33
34
      <year>2008</year>
 
35
      <year>2009</year>
 
36
      <year>2010</year>
 
37
      <year>2011</year>
 
38
      <year>2012</year>
 
39
      <year>2013</year>
 
40
      <year>2014</year>
 
41
      <year>2015</year>
 
42
      <year>2016</year>
 
43
      <year>2017</year>
34
44
      <holder>Teddy Hogeborn</holder>
35
45
      <holder>Björn Påhlsson</holder>
36
46
    </copyright>
37
 
    <legalnotice>
38
 
      <para>
39
 
        This manual page is free software: you can redistribute it
40
 
        and/or modify it under the terms of the GNU General Public
41
 
        License as published by the Free Software Foundation,
42
 
        either version 3 of the License, or (at your option) any
43
 
        later version.
44
 
      </para>
45
 
      
46
 
      <para>
47
 
        This manual page is distributed in the hope that it will
48
 
        be useful, but WITHOUT ANY WARRANTY; without even the
49
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
50
 
        PARTICULAR PURPOSE.  See the GNU General Public License
51
 
        for more details.
52
 
      </para>
53
 
      
54
 
      <para>
55
 
        You should have received a copy of the GNU General Public
56
 
        License along with this program; If not, see
57
 
        <ulink url="http://www.gnu.org/licenses/"/>.
58
 
      </para>
59
 
    </legalnotice>
 
47
    <xi:include href="../legalnotice.xml"/>
60
48
  </refentryinfo>
61
49
  
62
50
  <refmeta>
73
61
    <cmdsynopsis>
74
62
      <command>&COMMANDNAME;</command>
75
63
      <group choice="opt">
76
 
        <arg choice="plain"><option>-p <replaceable
 
64
        <arg choice="plain"><option>--prefix <replaceable
77
65
        >PREFIX</replaceable></option></arg>
78
 
        <arg choice="plain"><option>--prefix </option><replaceable
 
66
        <arg choice="plain"><option>-p </option><replaceable
79
67
        >PREFIX</replaceable></arg>
80
68
      </group>
 
69
      <sbr/>
81
70
      <arg choice="opt"><option>--debug</option></arg>
82
71
    </cmdsynopsis>
83
72
    <cmdsynopsis>
84
73
      <command>&COMMANDNAME;</command>
85
74
      <group choice="req">
 
75
        <arg choice="plain"><option>--help</option></arg>
86
76
        <arg choice="plain"><option>-?</option></arg>
87
 
        <arg choice="plain"><option>--help</option></arg>
88
77
      </group>
89
78
    </cmdsynopsis>
90
79
    <cmdsynopsis>
94
83
    <cmdsynopsis>
95
84
      <command>&COMMANDNAME;</command>
96
85
      <group choice="req">
 
86
        <arg choice="plain"><option>--version</option></arg>
97
87
        <arg choice="plain"><option>-V</option></arg>
98
 
        <arg choice="plain"><option>--version</option></arg>
99
88
      </group>
100
 
    </cmdsynopsis>    
 
89
    </cmdsynopsis>
101
90
  </refsynopsisdiv>
102
91
  
103
92
  <refsect1 id="description">
104
93
    <title>DESCRIPTION</title>
105
94
    <para>
106
95
      All <command>&COMMANDNAME;</command> does is prompt for a
107
 
      password and output any given password to standard output.  This
108
 
      is not very useful on its own.  This program is really meant to
109
 
      run as a plugin in the <application>Mandos</application>
110
 
      client-side system, where it is used as a fallback and
111
 
      alternative to retriving passwords from a <application
112
 
      >Mandos</application> server.
 
96
      password and output any given password to standard output.
 
97
    </para>
 
98
    <para>
 
99
      This program is not very useful on its own.  This program is
 
100
      really meant to run as a plugin in the <application
 
101
      >Mandos</application> client-side system, where it is used as a
 
102
      fallback and alternative to retrieving passwords from a
 
103
      <application >Mandos</application> server.
113
104
    </para>
114
105
    <para>
115
106
      This program is little more than a <citerefentry><refentrytitle
133
124
    
134
125
    <variablelist>
135
126
      <varlistentry>
136
 
        <term><option>-p</option> <replaceable>PREFIX</replaceable
137
 
        ></term>
138
 
        <term><option>--prefix=</option><replaceable
139
 
        >PREFIX</replaceable></term>
 
127
        <term><option>--prefix=<replaceable
 
128
        >PREFIX</replaceable></option></term>
 
129
        <term><option>-p
 
130
        <replaceable>PREFIX</replaceable></option></term>
140
131
        <listitem>
141
132
          <para>
142
133
            Prefix string shown before the password prompt.
156
147
      </varlistentry>
157
148
      
158
149
      <varlistentry>
 
150
        <term><option>--help</option></term>
159
151
        <term><option>-?</option></term>
160
 
        <term><option>--help</option></term>
161
152
        <listitem>
162
153
          <para>
163
154
            Gives a help message about options and their meanings.
175
166
      </varlistentry>
176
167
      
177
168
      <varlistentry>
 
169
        <term><option>--version</option></term>
178
170
        <term><option>-V</option></term>
179
 
        <term><option>--version</option></term>
180
171
        <listitem>
181
172
          <para>
182
173
            Prints the program version.
183
174
          </para>
184
175
        </listitem>
185
 
      </varlistentry>            
 
176
      </varlistentry>
186
177
    </variablelist>
187
178
  </refsect1>
188
179
  
200
191
    <title>ENVIRONMENT</title>
201
192
    <variablelist>
202
193
      <varlistentry>
203
 
        <term><envar>cryptsource</envar></term>
204
 
        <term><envar>crypttarget</envar></term>
 
194
        <term><envar>CRYPTTAB_SOURCE</envar></term>
 
195
        <term><envar>CRYPTTAB_NAME</envar></term>
205
196
        <listitem>
206
197
          <para>
207
198
            If set, these environment variables will be assumed to
215
206
          <manvolnum>8mandos</manvolnum></citerefentry>, which will
216
207
          normally have inherited them from
217
208
          <filename>/scripts/local-top/cryptroot</filename> in the
218
 
          initial RAM disk environment, which will have set them from
219
 
          parsing kernel arguments and
 
209
          initial <acronym>RAM</acronym> disk environment, which will
 
210
          have set them from parsing kernel arguments and
220
211
          <filename>/conf/conf.d/cryptroot</filename> (also in the
221
212
          initial RAM disk environment), which in turn will have been
222
213
          created when the initial RAM disk image was created by
236
227
  
237
228
  <refsect1 id="bugs">
238
229
    <title>BUGS</title>
239
 
    <para>
240
 
      None are known at this time.
241
 
    </para>
242
 
  </refsect1>  
 
230
    <xi:include href="../bugs.xml"/>
 
231
  </refsect1>
243
232
  
244
233
  <refsect1 id="example">
245
234
    <title>EXAMPLE</title>
261
250
      <para>
262
251
        Show a prefix before the prompt; in this case, a host name.
263
252
        It might be useful to be reminded of which host needs a
264
 
        password, in case of KVM switches, etc.
 
253
        password, in case of <acronym>KVM</acronym> switches, etc.
265
254
      </para>
266
255
      <para>
267
256
 
291
280
      >plugin-runner</refentrytitle><manvolnum>8mandos</manvolnum>
292
281
      </citerefentry>, and will, when run standalone, outside, in a
293
282
      normal environment, immediately output on its standard output
294
 
      any presumably secret password it just recieved.  Therefore,
 
283
      any presumably secret password it just received.  Therefore,
295
284
      when running this program standalone (which should never
296
285
      normally be done), take care not to type in any real secret
297
286
      password by force of habit, since it would then immediately be
309
298
  <refsect1 id="see_also">
310
299
    <title>SEE ALSO</title>
311
300
    <para>
 
301
      <citerefentry><refentrytitle>intro</refentrytitle>
 
302
      <manvolnum>8mandos</manvolnum></citerefentry>
312
303
      <citerefentry><refentrytitle>crypttab</refentrytitle>
313
304
      <manvolnum>5</manvolnum></citerefentry>
314
 
      <citerefentry><refentrytitle>password-request</refentrytitle>
 
305
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
315
306
      <manvolnum>8mandos</manvolnum></citerefentry>
316
307
      <citerefentry><refentrytitle>plugin-runner</refentrytitle>
317
308
      <manvolnum>8mandos</manvolnum></citerefentry>,