bzr branch
http://bzr.recompile.se/loggerhead/mandos/trunk
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
1 |
<?xml version="1.0" encoding="UTF-8"?>
|
95
by Teddy Hogeborn
* Makefile (MANPOST): Bug fix: corrected patterns. |
2 |
<!DOCTYPE section PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
3 |
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd">
|
4 |
||
5 |
<!--
|
|
6 |
This file is used by both mandos(8) and mandos.conf(5), since these
|
|
7 |
options can be used both on the command line and in the config file.
|
|
142
by Teddy Hogeborn
* plugins.d/password-request.c (main): Change default GnuTLS priority |
8 |
|
171
by Teddy Hogeborn
Renamed "password-request" to "mandos-client". |
9 |
It is also used for some texts by mandos-client(8mandos).
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
10 |
-->
|
11 |
||
91
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Include all DocBook-to-manpage-related |
12 |
<section>
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
13 |
<title/> |
14 |
|
|
15 |
<para id="interface"> |
|
16 |
If this is specified, the server will only announce the service |
|
105
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Only cd to one directory. |
17 |
and listen to requests on the specified network interface. |
18 |
Default is to use all available interfaces. <emphasis |
|
19 |
>Note:</emphasis> a failure to bind to the specified |
|
119
by Teddy Hogeborn
* mandos-clients.conf.xml (SYNOPSIS): Remove line breaks. |
20 |
interface is not considered critical, and the server will not |
21 |
exit, but instead continue normally. |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
22 |
</para> |
23 |
|
|
24 |
<para id="address"> |
|
95
by Teddy Hogeborn
* Makefile (MANPOST): Bug fix: corrected patterns. |
25 |
If this option is used, the server will only listen to the |
26 |
specified IPv6 address. If a link-local address is specified, an |
|
27 |
interface should be set, since a link-local address is only valid |
|
28 |
on a single interface. By default, the server will listen to all |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
29 |
available addresses. If set, this must normally be an IPv6 |
30 |
address; an IPv4 address can only be specified using IPv4-mapped |
|
31 |
IPv6 address syntax: <quote><systemitem class="ipaddress" |
|
32 |
>::FFFF:192.0.2.3</systemitem ></quote>. (Only if IPv6 usage is |
|
33 |
<emphasis>disabled</emphasis> (see below) must this be an IPv4 |
|
34 |
address.)
|
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
35 |
</para> |
36 |
|
|
37 |
<para id="port"> |
|
38 |
If this option is used, the server will bind to that port. By |
|
39 |
default, the server will listen to an arbitrary port given by the |
|
40 |
operating system. |
|
41 |
</para> |
|
42 |
|
|
43 |
<para id="debug"> |
|
44 |
If the server is run in debug mode, it will run in the foreground |
|
105
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Only cd to one directory. |
45 |
and print a lot of debugging information. The default is to |
46 |
<emphasis>not</emphasis> run in debug mode. |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
47 |
</para> |
48 |
|
|
777
by Teddy Hogeborn
Bug fix for GnuTLS 3: be compatible with old 2048-bit DSA keys. |
49 |
<para id="priority"> |
143
by Teddy Hogeborn
* Makefile (mandos.8): Add dependency on "overview.xml" and |
50 |
GnuTLS priority string for the <acronym>TLS</acronym> handshake. |
962
by Teddy Hogeborn
Add support for using raw public keys in TLS (RFC 7250) |
51 |
The default is |
52 |
<quote><literal>SECURE128​:!CTYPE-X.509​:+CTYPE-RAWPK​:!RSA​:!VERS-ALL​:+VERS-TLS1.3​:%PROFILE_ULTRA</literal></quote> |
|
53 |
when using raw public keys in TLS, and |
|
54 |
<quote><literal>SECURE256​:!CTYPE-X.509​:+CTYPE-OPENPGP​:!RSA​:+SIGN-DSA-SHA256</literal></quote> |
|
55 |
when using OpenPGP keys in TLS,. See <citerefentry><refentrytitle |
|
742
by Teddy Hogeborn
Add ":!RSA" to GnuTLS priority string, to disallow non-DHE kx. |
56 |
>gnutls_priority_init</refentrytitle> |
634
by Teddy Hogeborn
* debian/control (Build-Depends): Changed debhelper version to (>= 9) |
57 |
<manvolnum>3</manvolnum></citerefentry> for the syntax. |
58 |
<emphasis>Warning</emphasis>: changing this may make the |
|
59 |
<acronym>TLS</acronym> handshake fail, making server-client |
|
742
by Teddy Hogeborn
Add ":!RSA" to GnuTLS priority string, to disallow non-DHE kx. |
60 |
communication impossible. Changing this option may also make the |
61 |
network traffic decryptable by an attacker. |
|
634
by Teddy Hogeborn
* debian/control (Build-Depends): Changed debhelper version to (>= 9) |
62 |
</para> |
63 |
|
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
64 |
<para id="servicename"> |
65 |
Zeroconf service name. The default is |
|
66 |
<quote><literal>Mandos</literal></quote>. This only needs to be |
|
216
by Teddy Hogeborn
* Makefile: Add HTML rules for manual pages. |
67 |
changed if for some reason is would be necessary to run more than |
68 |
one server on the same <emphasis>host</emphasis>. This would not |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
69 |
normally be useful. If there are name collisions on the same |
70 |
<emphasis>network</emphasis>, the newer server will automatically |
|
71 |
rename itself to <quote><literal>Mandos #2</literal></quote>, and |
|
72 |
so on; therefore, this option is not needed in that case. |
|
73 |
</para> |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
74 |
|
243
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
75 |
<para id="dbus"> |
76 |
This option controls whether the server will provide a D-Bus |
|
77 |
system bus interface. The default is to provide such an |
|
78 |
interface.
|
|
79 |
</para> |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
80 |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
81 |
<para id="ipv6"> |
82 |
This option controls whether the server will use IPv6 sockets and |
|
83 |
addresses. The default is to use IPv6. This option should |
|
84 |
<emphasis>never</emphasis> normally be turned off, <emphasis>even in |
|
85 |
IPv4-only environments</emphasis>. This is because <citerefentry> |
|
86 |
<refentrytitle>mandos-client</refentrytitle> |
|
87 |
<manvolnum>8mandos</manvolnum></citerefentry> will normally use |
|
88 |
IPv6 link-local addresses, and will not be able to find or connect |
|
89 |
to the server if this option is turned off. <emphasis>Only |
|
90 |
advanced users should consider changing this option</emphasis>. |
|
91 |
</para> |
|
518.2.2
by Teddy Hogeborn
Directory with persistent state can now be changed with the "statedir" |
92 |
|
518.1.1
by Björn Påhlsson
Persistent state: New feature. Client state is now stored when mandos |
93 |
<para id="restore"> |
546
by Teddy Hogeborn
* debian/rules (binary-common): Exclude network-hooks.d from |
94 |
This option controls whether the server will restore its state |
95 |
from the last time it ran. Default is to restore last state. |
|
518.1.1
by Björn Påhlsson
Persistent state: New feature. Client state is now stored when mandos |
96 |
</para> |
314
by Teddy Hogeborn
Support not using IPv6 in server: |
97 |
|
518.2.2
by Teddy Hogeborn
Directory with persistent state can now be changed with the "statedir" |
98 |
<para id="statedir"> |
99 |
Directory to save (and restore) state in. Default is |
|
100 |
<quote><filename |
|
101 |
class="directory">/var/lib/mandos</filename></quote>. |
|
102 |
</para> |
|
103 |
|
|
589.1.1
by Teddy Hogeborn
* mandos: Implement "--socket" option. |
104 |
<para id="socket"> |
105 |
If this option is used, the server will not create a new network |
|
106 |
socket, but will instead use the supplied file descriptor. By |
|
107 |
default, the server will create a new network socket. |
|
108 |
</para> |
|
109 |
|
|
606
by Teddy Hogeborn
* mandos: New "--foreground" option. |
110 |
<para id="foreground"> |
111 |
This option will make the server run in the foreground and not |
|
112 |
write a PID file. The default is to <emphasis>not</emphasis> run |
|
113 |
in the foreground, except in <option>debug</option> mode, which |
|
114 |
implies this option. |
|
115 |
</para> |
|
116 |
|
|
707
by Teddy Hogeborn
mandos: New "--no-zeroconf" option. Also make "--socket=0" work. |
117 |
<para id="zeroconf"> |
118 |
This option controls whether the server will announce its |
|
119 |
existence using Zeroconf. Default is to use Zeroconf. If |
|
120 |
Zeroconf is not used, a <option>port</option> number or a |
|
121 |
<option>socket</option> is required. |
|
122 |
</para> |
|
123 |
|
|
91
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Include all DocBook-to-manpage-related |
124 |
</section>
|