bzr branch
http://bzr.recompile.se/loggerhead/mandos/trunk
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
1 |
<?xml version="1.0" encoding="UTF-8"?>
|
95
by Teddy Hogeborn
* Makefile (MANPOST): Bug fix: corrected patterns. |
2 |
<!DOCTYPE section PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
3 |
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd">
|
4 |
||
5 |
<!--
|
|
6 |
This file is used by both mandos(8) and mandos.conf(5), since these
|
|
7 |
options can be used both on the command line and in the config file.
|
|
142
by Teddy Hogeborn
* plugins.d/password-request.c (main): Change default GnuTLS priority |
8 |
|
171
by Teddy Hogeborn
Renamed "password-request" to "mandos-client". |
9 |
It is also used for some texts by mandos-client(8mandos).
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
10 |
-->
|
11 |
||
91
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Include all DocBook-to-manpage-related |
12 |
<section>
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
13 |
<title/> |
14 |
|
|
15 |
<para id="interface"> |
|
16 |
If this is specified, the server will only announce the service |
|
105
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Only cd to one directory. |
17 |
and listen to requests on the specified network interface. |
18 |
Default is to use all available interfaces. <emphasis |
|
19 |
>Note:</emphasis> a failure to bind to the specified |
|
119
by Teddy Hogeborn
* mandos-clients.conf.xml (SYNOPSIS): Remove line breaks. |
20 |
interface is not considered critical, and the server will not |
21 |
exit, but instead continue normally. |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
22 |
</para> |
23 |
|
|
24 |
<para id="address"> |
|
95
by Teddy Hogeborn
* Makefile (MANPOST): Bug fix: corrected patterns. |
25 |
If this option is used, the server will only listen to the |
26 |
specified IPv6 address. If a link-local address is specified, an |
|
27 |
interface should be set, since a link-local address is only valid |
|
28 |
on a single interface. By default, the server will listen to all |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
29 |
available addresses. If set, this must normally be an IPv6 |
30 |
address; an IPv4 address can only be specified using IPv4-mapped |
|
31 |
IPv6 address syntax: <quote><systemitem class="ipaddress" |
|
32 |
>::FFFF:192.0.2.3</systemitem ></quote>. (Only if IPv6 usage is |
|
33 |
<emphasis>disabled</emphasis> (see below) must this be an IPv4 |
|
34 |
address.)
|
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
35 |
</para> |
36 |
|
|
37 |
<para id="port"> |
|
38 |
If this option is used, the server will bind to that port. By |
|
39 |
default, the server will listen to an arbitrary port given by the |
|
40 |
operating system. |
|
41 |
</para> |
|
42 |
|
|
43 |
<para id="debug"> |
|
44 |
If the server is run in debug mode, it will run in the foreground |
|
105
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Only cd to one directory. |
45 |
and print a lot of debugging information. The default is to |
46 |
<emphasis>not</emphasis> run in debug mode. |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
47 |
</para> |
48 |
|
|
634
by Teddy Hogeborn
* debian/control (Build-Depends): Changed debhelper version to (>= 9) |
49 |
<para id="priority_compat"> |
143
by Teddy Hogeborn
* Makefile (mandos.8): Add dependency on "overview.xml" and |
50 |
GnuTLS priority string for the <acronym>TLS</acronym> handshake. |
51 |
The default is <quote><literal |
|
634
by Teddy Hogeborn
* debian/control (Build-Depends): Changed debhelper version to (>= 9) |
52 |
>SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:+SIGN-RSA-SHA224:</literal> |
53 |
<literal>+SIGN-RSA-RMD160</literal></quote>. |
|
618
by Teddy Hogeborn
* mandos: Bug fix: Make boolean options work from the config file |
54 |
See <citerefentry><refentrytitle |
55 |
>gnutls_priority_init</refentrytitle> |
|
116
by Teddy Hogeborn
* mandos-options.xml (priority): Added <acronym> tags. |
56 |
<manvolnum>3</manvolnum></citerefentry> for the syntax. |
57 |
<emphasis>Warning</emphasis>: changing this may make the |
|
143
by Teddy Hogeborn
* Makefile (mandos.8): Add dependency on "overview.xml" and |
58 |
<acronym>TLS</acronym> handshake fail, making server-client |
59 |
communication impossible. |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
60 |
</para> |
61 |
|
|
634
by Teddy Hogeborn
* debian/control (Build-Depends): Changed debhelper version to (>= 9) |
62 |
<para id="priority"> |
63 |
GnuTLS priority string for the <acronym>TLS</acronym> handshake. |
|
64 |
The default is <quote><literal |
|
65 |
>SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP</literal></quote>. See |
|
66 |
<citerefentry><refentrytitle >gnutls_priority_init</refentrytitle> |
|
67 |
<manvolnum>3</manvolnum></citerefentry> for the syntax. |
|
68 |
<emphasis>Warning</emphasis>: changing this may make the |
|
69 |
<acronym>TLS</acronym> handshake fail, making server-client |
|
70 |
communication impossible. |
|
71 |
</para> |
|
72 |
|
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
73 |
<para id="servicename"> |
74 |
Zeroconf service name. The default is |
|
75 |
<quote><literal>Mandos</literal></quote>. This only needs to be |
|
216
by Teddy Hogeborn
* Makefile: Add HTML rules for manual pages. |
76 |
changed if for some reason is would be necessary to run more than |
77 |
one server on the same <emphasis>host</emphasis>. This would not |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
78 |
normally be useful. If there are name collisions on the same |
79 |
<emphasis>network</emphasis>, the newer server will automatically |
|
80 |
rename itself to <quote><literal>Mandos #2</literal></quote>, and |
|
81 |
so on; therefore, this option is not needed in that case. |
|
82 |
</para> |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
83 |
|
243
by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a |
84 |
<para id="dbus"> |
85 |
This option controls whether the server will provide a D-Bus |
|
86 |
system bus interface. The default is to provide such an |
|
87 |
interface.
|
|
88 |
</para> |
|
90
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Added "--xinclude". |
89 |
|
314
by Teddy Hogeborn
Support not using IPv6 in server: |
90 |
<para id="ipv6"> |
91 |
This option controls whether the server will use IPv6 sockets and |
|
92 |
addresses. The default is to use IPv6. This option should |
|
93 |
<emphasis>never</emphasis> normally be turned off, <emphasis>even in |
|
94 |
IPv4-only environments</emphasis>. This is because <citerefentry> |
|
95 |
<refentrytitle>mandos-client</refentrytitle> |
|
96 |
<manvolnum>8mandos</manvolnum></citerefentry> will normally use |
|
97 |
IPv6 link-local addresses, and will not be able to find or connect |
|
98 |
to the server if this option is turned off. <emphasis>Only |
|
99 |
advanced users should consider changing this option</emphasis>. |
|
100 |
</para> |
|
518.2.2
by Teddy Hogeborn
Directory with persistent state can now be changed with the "statedir" |
101 |
|
518.1.1
by Björn Påhlsson
Persistent state: New feature. Client state is now stored when mandos |
102 |
<para id="restore"> |
546
by Teddy Hogeborn
* debian/rules (binary-common): Exclude network-hooks.d from |
103 |
This option controls whether the server will restore its state |
104 |
from the last time it ran. Default is to restore last state. |
|
518.1.1
by Björn Påhlsson
Persistent state: New feature. Client state is now stored when mandos |
105 |
</para> |
314
by Teddy Hogeborn
Support not using IPv6 in server: |
106 |
|
518.2.2
by Teddy Hogeborn
Directory with persistent state can now be changed with the "statedir" |
107 |
<para id="statedir"> |
108 |
Directory to save (and restore) state in. Default is |
|
109 |
<quote><filename |
|
110 |
class="directory">/var/lib/mandos</filename></quote>. |
|
111 |
</para> |
|
112 |
|
|
589.1.1
by Teddy Hogeborn
* mandos: Implement "--socket" option. |
113 |
<para id="socket"> |
114 |
If this option is used, the server will not create a new network |
|
115 |
socket, but will instead use the supplied file descriptor. By |
|
116 |
default, the server will create a new network socket. |
|
117 |
</para> |
|
118 |
|
|
606
by Teddy Hogeborn
* mandos: New "--foreground" option. |
119 |
<para id="foreground"> |
120 |
This option will make the server run in the foreground and not |
|
121 |
write a PID file. The default is to <emphasis>not</emphasis> run |
|
122 |
in the foreground, except in <option>debug</option> mode, which |
|
123 |
implies this option. |
|
124 |
</para> |
|
125 |
|
|
91
by Teddy Hogeborn
* Makefile (DOCBOOKTOMAN): Include all DocBook-to-manpage-related |
126 |
</section>
|