2
configuration for OpenPGP key dir
3
header files/symbols tally
4
check exit codes of all system calls
6
protocol version header
7
use strsep instead of strtok?
10
header files/symbols tally
11
check exit codes of all system calls
12
change uid to nobody:nogroup
13
other drop privs stuff?
14
pass things in environment, like device name, etc
15
Does cryptsetup already do this?
16
use strsep instead of strtok?
21
protocol version header
22
Run-time communication with server
25
[Mandos-tools/utilities]
3
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]]
8
** TODO [#A] Wireless network hook
9
** TODO [#B] Use capabilities instead of seteuid().
10
** TODO [#B] Use struct sockaddr_storage instead of a union
11
** TODO [#B] Use getaddrinfo(hints=AI_NUMERICHOST) instead of inet_pton()
12
** TODO [#B] Use getnameinfo(serv=NULL, NI_NUMERICHOST) instead of inet_ntop()
13
** TODO [#B] Prefer /run/tmp over /tmp, if it exists
16
** TODO [#B] use scandir(3) instead of readdir(3)
18
* usplash (Deprecated)
19
** TODO [#A] Make it work again
20
** TODO [#B] use scandir(3) instead of readdir(3)
21
** TODO Use [[info:libc:Argz%20Functions][argz_extract]]
24
** TODO [#B] Drop privileges after opening FIFO.
27
** TODO [#B] lock stdin (with flock()?)
34
** TODO handle printing for errors for plugins
35
*** Hook up stderr of plugins, buffer them, and prepend mandos pluig [plugin name]
36
** TODO [#B] use scandir(3) instead of readdir(3)
37
** TODO [#C] use same file name rules as run-parts(8)
38
** kernel command line option for debug info
39
** TODO [#B] Use openat()
42
** TODO Document why we ignore sigint
43
** TODO [#B] Log level :BUGS:
44
*** TODO /etc/mandos/clients.d/*.conf
45
Watch this directory and add/remove/update clients?
46
** TODO [#C] config for TXT record
47
** TODO Log level dbus option
48
SetLogLevel D-Bus call
49
** TODO Implement --foreground :BUGS:
50
[[info:standards:Option%20Table][Table of Long Options]]
51
** TODO Implement --socket
52
[[info:standards:Option%20Table][Table of Long Options]]
53
** TODO [#C] DBusServiceObjectUsingSuper
54
** TODO [#B] Global enable/disable flag
55
** TODO [#B] By-client countdown on number of secrets given
56
** TODO [#B] Support RFC 3339 time duration syntax
58
*** NeedsPassword(50) - Timeout, default disapprove
59
+ SetPass(u"gazonk", True) -> Approval, persistent
60
+ Approve(False) -> Close client connection immediately
61
** TODO [#C] python-parsedatetime
62
** TODO [#C] systemd/launchd
63
http://0pointer.de/blog/projects/systemd.html
64
http://wiki.debian.org/systemd
65
** TODO Separate logging logic to own object
66
** TODO [#A] Limit approval_delay to max gnutls/tls timeout value
67
** TODO [#B] break the wait on approval_delay if connection dies
68
** TODO Generate Client.runtime_expansions from client options + extra
69
** TODO Allow %%(checker)s as a runtime expansion
70
** TODO Use python-tlslite?
71
** TODO D-Bus AddClient() method on server object
72
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods.
73
** TODO Emit [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-properties][org.freedesktop.DBus.Properties.PropertiesChanged]] signal
74
TODO Deprecate se.recompile.Mandos.Client.PropertyChanged - annotate!
75
TODO Can use "invalidates" annotation to also emit on changed secret.
76
** TODO Support [[http://dbus.freedesktop.org/doc/dbus-specification.html#standard-interfaces-objectmanager][org.freedesktop.DBus.ObjectManager]] interface on server object
77
Deprecate methods GetAllClients(), GetAllClientsWithProperties()
78
and signals ClientAdded and ClientRemoved.
81
** Add mandos contact info in manual pages
84
*** Handle "no D-Bus server" and/or "no Mandos server found" better
85
*** [#B] --dump option
86
** TODO Support RFC 3339 time duration syntax
88
* TODO mandos-dispatch
89
Listens for specified D-Bus signals and spawns shell commands with
93
** TODO help should be toggleable
94
** Urwid client data displayer
95
Better view of client data in the listing
97
** Print a nice "We are sorry" message, save stack trace to log.
98
** Show timeout countdown for approval
101
** TODO "--secfile" option
102
Using the "secfile" option instead of "secret"
103
** TODO [#B] "--test" option
104
For testing decryption before rebooting.
107
** TODO [#C] Implement DEB_BUILD_OPTIONS
108
http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
111
** /usr/share/initramfs-tools/hooks/mandos
112
*** TODO [#C] use same file name rules as run-parts(8)
113
*** TODO [#C] Do not install in initrd.img if configured not to.
114
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
115
** TODO [#C] /etc/bash_completion.d/mandos
116
From XML sources directly?
119
** TODO Locate which package moves the other bin/sh when busybox is deactivated
120
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox