2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY COMMANDNAME "mandos-client">
5
<!ENTITY TIMESTAMP "2011-10-03">
5
<!ENTITY TIMESTAMP "2009-01-04">
6
6
<!ENTITY % common SYSTEM "../common.ent">
19
19
<firstname>Björn</firstname>
20
20
<surname>Påhlsson</surname>
22
<email>belorn@recompile.se</email>
22
<email>belorn@fukt.bsnet.se</email>
26
26
<firstname>Teddy</firstname>
27
27
<surname>Hogeborn</surname>
29
<email>teddy@recompile.se</email>
29
<email>teddy@fukt.bsnet.se</email>
37
36
<holder>Teddy Hogeborn</holder>
38
37
<holder>Björn Påhlsson</holder>
135
126
<command>&COMMANDNAME;</command> is a client program that
136
127
communicates with <citerefentry><refentrytitle
137
128
>mandos</refentrytitle><manvolnum>8</manvolnum></citerefentry>
138
to get a password. In slightly more detail, this client program
139
brings up a network interface, uses the interface’s IPv6
140
link-local address to get network connectivity, uses Zeroconf to
141
find servers on the local network, and communicates with servers
142
using TLS with an OpenPGP key to ensure authenticity and
143
confidentiality. This client program keeps running, trying all
144
servers on the network, until it receives a satisfactory reply
145
or a TERM signal. After all servers have been tried, all
146
servers are periodically retried. If no servers are found it
147
will wait indefinitely for new servers to appear.
129
to get a password. It uses IPv6 link-local addresses to get
130
network connectivity, Zeroconf to find servers, and TLS with an
131
OpenPGP key to ensure authenticity and confidentiality. It
132
keeps running, trying all servers on the network, until it
133
receives a satisfactory reply or a TERM signal is received.
150
136
This program is not meant to be run directly; it is really meant
207
<term><option>--interface=<replaceable
208
>NAME</replaceable></option></term>
193
<term><option>--interface=
194
<replaceable>NAME</replaceable></option></term>
210
196
<replaceable>NAME</replaceable></option></term>
213
199
Network interface that will be brought up and scanned for
214
Mandos servers to connect to. The default is the empty
215
string, which will automatically choose an appropriate
200
Mandos servers to connect to. The default it
201
<quote><literal>eth0</literal></quote>.
219
204
If the <option>--connect</option> option is used, this
220
205
specifies the interface to use to connect to the address
224
Note that since this program will normally run in the
225
initial RAM disk environment, the interface must be an
226
interface which exists at that stage. Thus, the interface
227
can not be a pseudo-interface such as <quote>br0</quote>
228
or <quote>tun0</quote>; such interfaces will not exist
229
until much later in the boot process, and can not be used
233
<replaceable>NAME</replaceable> can be the string
234
<quote><literal>none</literal></quote>; this will not use
235
any specific interface, and will not bring up an interface
236
on startup. This is not recommended, and only meant for
307
<term><option>--retry=<replaceable
308
>SECONDS</replaceable></option></term>
311
All Mandos servers are tried repeatedly until a password
312
is received. This value specifies, in seconds, how long
313
between each successive try <emphasis>for the same
314
server</emphasis>. The default is 10 seconds.
320
<term><option>--network-hook-dir=<replaceable
321
>DIR</replaceable></option></term>
324
Network hook directory. The default directory is
325
<quote><filename class="directory"
326
>/lib/mandos/network-hooks.d</filename></quote>.
332
276
<term><option>--debug</option></term>
405
349
server could be found and the password received from it could be
406
350
successfully decrypted and output on standard output. The
407
351
program will exit with a non-zero exit status only if a critical
408
error occurs. Otherwise, it will forever connect to any
409
discovered <application>Mandos</application> servers, trying to
410
get a decryptable password and print it.
352
error occurs. Otherwise, it will forever connect to new
353
<application>Mandos</application> servers as they appear, trying
354
to get a decryptable password and print it.
488
432
<informalexample>
490
434
Run in debug mode, with a custom key, and do not use Zeroconf
491
to locate a server; connect directly to the IPv6 link-local
492
address <quote><systemitem class="ipaddress"
493
>fe80::aede:48ff:fe71:f6f2</systemitem></quote>, port 4711,
494
using interface eth2:
435
to locate a server; connect directly to the IPv6 address
436
<quote><systemitem class="ipaddress"
437
>2001:db8:f983:bd0b:30de:ae4a:71f2:f672</systemitem></quote>,
438
port 4711, using interface eth2:
498
442
<!-- do not wrap this line -->
499
<userinput>&COMMANDNAME; --debug --pubkey keydir/pubkey.txt --seckey keydir/seckey.txt --connect fe80::aede:48ff:fe71:f6f2:4711 --interface eth2</userinput>
443
<userinput>&COMMANDNAME; --debug --pubkey keydir/pubkey.txt --seckey keydir/seckey.txt --connect 2001:db8:f983:bd0b:30de:ae4a:71f2:f672:4711 --interface eth2</userinput>
502
446
</informalexample>
552
496
<refsect1 id="see_also">
553
497
<title>SEE ALSO</title>
555
<citerefentry><refentrytitle>intro</refentrytitle>
556
<manvolnum>8mandos</manvolnum></citerefentry>,
557
499
<citerefentry><refentrytitle>cryptsetup</refentrytitle>
558
500
<manvolnum>8</manvolnum></citerefentry>,
559
501
<citerefentry><refentrytitle>crypttab</refentrytitle>