/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
1
-*- org -*-
2
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
3
* _attribute_((nonnull))
4
171 by Teddy Hogeborn
Renamed "password-request" to "mandos-client".
5
* mandos-client
355 by Teddy Hogeborn
* mandos: White-space fixes only.
6
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
7
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
8
** TODO use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
9
** TODO [#B] Retry a server which has a non-definite reply:
363 by Teddy Hogeborn
* plugin-runner.c: Minor stylistic changes.
10
*** A closed connection during the TLS handshake
11
*** A TCP timeout
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
12
** TODO [#B] Use capabilities instead of seteuid().
413 by Teddy Hogeborn
TODO file changes.
13
** TODO [#A] Retry --connect forever
355 by Teddy Hogeborn
* mandos: White-space fixes only.
14
15
* splashy
16
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
17
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
18
** TODO [#B] use error() instead of perror()
355 by Teddy Hogeborn
* mandos: White-space fixes only.
19
20
* usplash
414 by Teddy Hogeborn
Bug fix: mandos-client needs GnuPG but lacked a dependency on it. The
21
** TODO [#A] Make it work again
355 by Teddy Hogeborn
* mandos: White-space fixes only.
22
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
23
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
24
** TODO [#B] use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
25
26
* askpass-fifo
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
27
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
28
** TODO [#B] use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
29
** TODO [#B] Drop privileges after opening FIFO.
358 by Teddy Hogeborn
* plugins.d/mandos-client.c (start_mandos_communication): Check
30
31
* password-prompt
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
32
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
33
** TODO [#B] use error() instead of perror()
34
** TODO [#B] lock stdin (with flock()?)
355 by Teddy Hogeborn
* mandos: White-space fixes only.
35
413 by Teddy Hogeborn
TODO file changes.
36
* TODO [#B] passdev
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
37
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
38
* plugin-runner
39
** TODO [#B] use scandir(3) instead of readdir(3)
344 by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1".
40
** TODO [#C] use same file name rules as run-parts(8)
24.1.145 by Björn Påhlsson
todo
41
** kernel command line option for debug info
413 by Teddy Hogeborn
TODO file changes.
42
** TODO [#B] use error() instead of perror()
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
43
** TODO [$B] Use openat() and readdir64()
44
   http://udrepper.livejournal.com/19395.html
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
45
87 by Teddy Hogeborn
* Makefile: Bug fix: fixed creation of man pages in "plugins.d".
46
* mandos (server)
413 by Teddy Hogeborn
TODO file changes.
47
** TODO [#B] Log level							  :BUGS:
48
** TODO Persistent state						  :BUGS:
49
   /var/lib/mandos/*
50
*** TODO /etc/mandos/clients.d/*.conf
51
    Watch this directory and add/remove/update clients?
52
** TODO [#C] config for TXT record
53
** TODO Log level option
54
   syslogger.setLevel(logging.WARNING)
55
   + SetLogLevel D-Bus call
56
** TODO Implement --foreground						  :BUGS:
182 by Teddy Hogeborn
* Makefile (install): Use "install-client-nokey".
57
   [[info:standards:Option%20Table][Table of Long Options]]
58
** TODO Implement --socket
59
   [[info:standards:Option%20Table][Table of Long Options]]
413 by Teddy Hogeborn
TODO file changes.
60
** TODO Date+time on console log messages				  :BUGS:
64 by Teddy Hogeborn
* mandos-client.c (print_out_password): Strip trailing '\n'.
61
   Is this the default?
413 by Teddy Hogeborn
TODO file changes.
62
** TODO [#C] DBusServiceObjectUsingSuper
63
** TODO [#B] Global enable/disable flag
64
** TODO [#B] By-client countdown on secrets given
65
** TODO [#B] Fix problem with fsck taking a really long time
367 by Teddy Hogeborn
* init.d-mandos: Bug fix: Correct the LSB header.
66
   Whenever a client successfully gets a secret it could get a
67
   one-time timeout boost to allow for an fsck-incurred delay
413 by Teddy Hogeborn
TODO file changes.
68
** TODO [#A] Delay before client receives key
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
69
   This would give an operator opportunity to cancel the request if
70
   desired.
413 by Teddy Hogeborn
TODO file changes.
71
** TODO [#A] Client manual approval mode
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
72
   A client needs manual approval on the server before it gets the
73
   secret
413 by Teddy Hogeborn
TODO file changes.
74
** TODO [#B] Support RFC 3339 time duration syntax
416.1.1 by Teddy Hogeborn
Initial design on approval system.
75
** More D-Bus methods
76
*** NeedsApproval(50, True) -> timeout, default approve
77
    Default approval is configurable, but True by default
78
    + Approval(True) -> approve sending saved
79
    + Approval(False) -> Close client connection immediately
80
*** NeedsPassword(50) - Timeout, default disapprove
81
    + SetPass(u"gazonk", True) -> Approval, persistent
82
    + Approval(False) -> Close client connection immediately
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
83
** TODO [#C] python-parsedatetime
84
** TODO [#C] systemd/launchd
85
   http://0pointer.de/blog/projects/systemd.html
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
86
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
87
* mandos.xml
88
** [[file:mandos.xml::XXX][Document D-Bus interface]]
413 by Teddy Hogeborn
TODO file changes.
89
   Remove mention of lack of such interface in BUGS section
24.1.143 by Björn Påhlsson
added documentation todo
90
** Add mandos contact info in manual pages
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
91
413 by Teddy Hogeborn
TODO file changes.
92
* TODO [#A] Provide and install /etc/dbus-1/system.d/mandos.conf
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
93
308 by Teddy Hogeborn
* plugin-runner.c: Comment change.
94
* mandos-ctl
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
95
*** Handle "no D-Bus server" and/or "no Mandos server found" better
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
96
*** [#B] --dump option
411 by Teddy Hogeborn
More consistent terminology: Clients are no longer "invalid" - they
97
** TODO Support RFC 3339 time duration syntax
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
98
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
99
* TODO mandos-dispatch
100
  Listens for specified D-Bus signals and spawns shell commands with
101
  arguments.
102
375 by Teddy Hogeborn
* TODO: Updated.
103
* mandos-monitor
386 by Teddy Hogeborn
* mandos (DBusObjectWithProperties.Introspect): Add the name
104
** Urwid client data displayer
413 by Teddy Hogeborn
TODO file changes.
105
   Better view of client data in the listing
327 by Teddy Hogeborn
Merge from pipe IPC branch.
106
*** Properties popup
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
107
228 by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network
108
* mandos-keygen
24.1.126 by Björn Påhlsson
small stuff
109
** TODO Loop until passwords match when run interactively
228 by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network
110
** TODO "--secfile" option
111
   Using the "secfile" option instead of "secret"
112
** TODO [#B] "--test" option
113
   For testing decryption before rebooting.
67 by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on
114
370 by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3".
115
* Makefile
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
116
** TODO Add "--Xlinker --as-needed"
117
   http://udrepper.livejournal.com/19395.html
413 by Teddy Hogeborn
TODO file changes.
118
** TODO [#C] Implement DEB_BUILD_OPTIONS
370 by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3".
119
   http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
120
275 by Teddy Hogeborn
* debian/mandos-client.postinst: Converted to Bourne shell. Also
121
* Package
67 by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on
122
** /usr/share/initramfs-tools/hooks/mandos
344 by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1".
123
*** TODO [#C] use same file name rules as run-parts(8)
263 by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and
124
*** TODO [#C] Do not install in initrd.img if configured not to.
308 by Teddy Hogeborn
* plugin-runner.c: Comment change.
125
    Use "/etc/initramfs-tools/hooksconf.d/mandos"?
263 by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and
126
** TODO [#C] /etc/bash_completion.d/mandos
88 by Teddy Hogeborn
No code or documentation changes.
127
   From XML sources directly?
24.1.30 by Björn Påhlsson
Added more stuff to do
128
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
129

130
#+STARTUP: showall