/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2008-08-29 05:53:59 UTC
  • Revision ID: teddy@fukt.bsnet.se-20080829055359-wkdasnyxtylmnxus
* mandos.xml (EXAMPLE): Replaced all occurences of command name with
                        "&COMMANDNAME;".

* plugins.d/password-prompt.c (main): Improved some documentation
                                      strings.  Do perror() of
                                      tcgetattr() fails.  Add debug
                                      output if interrupted by signal.
                                      Loop over write() instead of
                                      using fwrite() when outputting
                                      password.  Add debug output if
                                      getline() returns 0, unless it
                                      was caused by a signal.  Add
                                      exit status code to debug
                                      output.

* plugins.d/password-prompt.xml: Changed all single quotes to double
                                 quotes for consistency.  Removed
                                 <?xml-stylesheet>.
  (ENTITY TIMESTAMP): New.  Automatically updated by Emacs time-stamp
                      by using Emacs local variables.
  (/refentry/refentryinfo/title): Changed to "Mandos Manual".
  (/refentry/refentryinfo/productname): Changed to "Mandos".
  (/refentry/refentryinfo/date): New; set to "&TIMESTAMP;".
  (/refentry/refentryinfo/copyright): Split copyright holders.
  (/refentry/refnamediv/refpurpose): Improved wording.
  (SYNOPSIS): Fix to use correct markup.  Add short options.
  (DESCRIPTION, OPTIONS): Improved wording.
  (OPTIONS): Improved wording.  Use more correct markup.  Document
             short options.
  (EXIT STATUS): Add text.
  (ENVIRONMENT): Document use of "cryptsource" and "crypttarget".
  (FILES): REMOVED.
  (BUGS): Add text.
  (EXAMPLE): Added some examples.
  (SECURITY): Added text.
  (SEE ALSO): Remove reference to mandos(8).  Add reference to
              crypttab(5).

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version="1.0" encoding="UTF-8"?>
 
1
<?xml version='1.0' encoding='UTF-8'?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
 
4
<!ENTITY VERSION "1.0">
4
5
<!ENTITY CONFNAME "mandos.conf">
5
6
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
6
 
<!ENTITY TIMESTAMP "2023-04-30">
7
 
<!ENTITY % common SYSTEM "common.ent">
8
 
%common;
9
7
]>
10
8
 
11
9
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
10
  <refentryinfo>
13
 
    <title>Mandos Manual</title>
 
11
    <title>&CONFNAME;</title>
14
12
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
15
 
    <productname>Mandos</productname>
16
 
    <productnumber>&version;</productnumber>
17
 
    <date>&TIMESTAMP;</date>
 
13
    <productname>&CONFNAME;</productname>
 
14
    <productnumber>&VERSION;</productnumber>
18
15
    <authorgroup>
19
16
      <author>
20
17
        <firstname>Björn</firstname>
21
18
        <surname>Påhlsson</surname>
22
19
        <address>
23
 
          <email>belorn@recompile.se</email>
 
20
          <email>belorn@fukt.bsnet.se</email>
24
21
        </address>
25
22
      </author>
26
23
      <author>
27
24
        <firstname>Teddy</firstname>
28
25
        <surname>Hogeborn</surname>
29
26
        <address>
30
 
          <email>teddy@recompile.se</email>
 
27
          <email>teddy@fukt.bsnet.se</email>
31
28
        </address>
32
29
      </author>
33
30
    </authorgroup>
34
31
    <copyright>
35
32
      <year>2008</year>
36
 
      <year>2009</year>
37
 
      <year>2010</year>
38
 
      <year>2011</year>
39
 
      <year>2012</year>
40
 
      <year>2013</year>
41
 
      <year>2014</year>
42
 
      <year>2015</year>
43
 
      <year>2016</year>
44
 
      <year>2017</year>
45
 
      <year>2018</year>
46
 
      <year>2019</year>
47
33
      <holder>Teddy Hogeborn</holder>
48
34
      <holder>Björn Påhlsson</holder>
49
35
    </copyright>
50
 
    <xi:include href="legalnotice.xml"/>
 
36
    <legalnotice>
 
37
      <para>
 
38
        This manual page is free software: you can redistribute it
 
39
        and/or modify it under the terms of the GNU General Public
 
40
        License as published by the Free Software Foundation,
 
41
        either version 3 of the License, or (at your option) any
 
42
        later version.
 
43
      </para>
 
44
 
 
45
      <para>
 
46
        This manual page is distributed in the hope that it will
 
47
        be useful, but WITHOUT ANY WARRANTY; without even the
 
48
        implied warranty of MERCHANTABILITY or FITNESS FOR A
 
49
        PARTICULAR PURPOSE.  See the GNU General Public License
 
50
        for more details.
 
51
      </para>
 
52
 
 
53
      <para>
 
54
        You should have received a copy of the GNU General Public
 
55
        License along with this program; If not, see
 
56
        <ulink url="http://www.gnu.org/licenses/"/>.
 
57
      </para>
 
58
    </legalnotice>
51
59
  </refentryinfo>
52
 
  
 
60
 
53
61
  <refmeta>
54
62
    <refentrytitle>&CONFNAME;</refentrytitle>
55
63
    <manvolnum>5</manvolnum>
61
69
      Configuration file for the Mandos server
62
70
    </refpurpose>
63
71
  </refnamediv>
64
 
  
 
72
 
65
73
  <refsynopsisdiv>
66
 
    <synopsis>&CONFPATH;</synopsis>
 
74
    <synopsis>
 
75
      &CONFPATH;
 
76
    </synopsis>
67
77
  </refsynopsisdiv>
68
 
  
 
78
 
69
79
  <refsect1 id="description">
70
80
    <title>DESCRIPTION</title>
71
81
    <para>
72
 
      The file &CONFPATH; is a configuration file for
 
82
      The file &CONFPATH; is a simple configuration file for
73
83
      <citerefentry><refentrytitle>mandos</refentrytitle>
74
84
      <manvolnum>8</manvolnum></citerefentry>, and is read by it at
75
85
      startup.  The configuration file starts with <quote><literal
83
93
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
84
94
      to provide comments.
85
95
    </para>
86
 
    
 
96
 
87
97
  </refsect1>
88
98
  <refsect1>
89
99
    <title>OPTIONS</title>
90
100
    
91
101
    <variablelist>
92
102
      <varlistentry>
93
 
        <term><option>interface<literal> = </literal><replaceable
94
 
        >NAME</replaceable></option></term>
 
103
        <term><varname>interface</varname></term>
95
104
        <listitem>
 
105
          <synopsis><literal>interface = </literal><replaceable
 
106
          >NAME</replaceable>
 
107
          </synopsis>
96
108
          <xi:include href="mandos-options.xml" xpointer="interface"/>
97
109
        </listitem>
98
110
      </varlistentry>
99
 
      
 
111
 
100
112
      <varlistentry>
101
 
        <term><option>address<literal> = </literal><replaceable
102
 
          >ADDRESS</replaceable></option></term>
 
113
        <term><varname>address</varname></term>
103
114
        <listitem>
 
115
          <synopsis><literal>address = </literal><replaceable
 
116
          >ADDRESS</replaceable>
 
117
          </synopsis>
104
118
          <xi:include href="mandos-options.xml" xpointer="address"/>
105
119
        </listitem>
106
120
      </varlistentry>
107
 
      
 
121
 
108
122
      <varlistentry>
109
 
        <term><option>port<literal> = </literal><replaceable
110
 
        >NUMBER</replaceable></option></term>
 
123
        <term><varname>port</varname></term>
111
124
        <listitem>
 
125
          <synopsis><literal>port = </literal><replaceable
 
126
          >NUMBER</replaceable>
 
127
          </synopsis>
112
128
          <xi:include href="mandos-options.xml" xpointer="port"/>
113
129
        </listitem>
114
130
      </varlistentry>
115
 
      
 
131
 
116
132
      <varlistentry>
117
 
        <term><option>debug<literal> = </literal>{ <literal
 
133
        <term><varname>debug</varname></term>
 
134
        <listitem>
 
135
          <synopsis><literal>debug = </literal>{ <literal
118
136
          >1</literal> | <literal>yes</literal> | <literal
119
137
          >true</literal> | <literal>on</literal> | <literal
120
138
          >0</literal> | <literal>no</literal> | <literal
121
 
          >false</literal> | <literal>off</literal> }</option></term>
122
 
        <listitem>
 
139
          >false</literal> | <literal>off</literal> }
 
140
          </synopsis>
123
141
          <xi:include href="mandos-options.xml" xpointer="debug"/>
124
142
        </listitem>
125
143
      </varlistentry>
126
 
      
 
144
 
127
145
      <varlistentry>
128
 
        <term><option>priority<literal> = </literal><replaceable
129
 
        >STRING</replaceable></option></term>
 
146
        <term><varname>priority</varname></term>
130
147
        <listitem>
 
148
          <synopsis><literal>priority = </literal><replaceable
 
149
          >STRING</replaceable>
 
150
          </synopsis>
131
151
          <xi:include href="mandos-options.xml" xpointer="priority"/>
132
152
        </listitem>
133
153
      </varlistentry>
134
 
      
 
154
 
135
155
      <varlistentry>
136
 
        <term><option>servicename<literal> = </literal
137
 
        ><replaceable>NAME</replaceable></option></term>
 
156
        <term><varname>servicename</varname></term>
138
157
        <listitem>
 
158
          <synopsis><literal>servicename = </literal><replaceable
 
159
          >NAME</replaceable>
 
160
          </synopsis>
139
161
          <xi:include href="mandos-options.xml"
140
162
                      xpointer="servicename"/>
141
163
        </listitem>
142
164
      </varlistentry>
143
165
      
144
 
      <varlistentry>
145
 
        <term><option>use_dbus<literal> = </literal>{ <literal
146
 
          >1</literal> | <literal>yes</literal> | <literal
147
 
          >true</literal> | <literal>on</literal> | <literal
148
 
          >0</literal> | <literal>no</literal> | <literal
149
 
          >false</literal> | <literal>off</literal> }</option></term>
150
 
        <listitem>
151
 
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
152
 
        </listitem>
153
 
      </varlistentry>
154
 
      
155
 
      <varlistentry>
156
 
        <term><option>use_ipv6<literal> = </literal>{ <literal
157
 
          >1</literal> | <literal>yes</literal> | <literal
158
 
          >true</literal> | <literal>on</literal> | <literal
159
 
          >0</literal> | <literal>no</literal> | <literal
160
 
          >false</literal> | <literal>off</literal> }</option></term>
161
 
        <listitem>
162
 
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
163
 
        </listitem>
164
 
      </varlistentry>
165
 
      
166
 
      <varlistentry>
167
 
        <term><option>restore<literal> = </literal>{ <literal
168
 
          >1</literal> | <literal>yes</literal> | <literal
169
 
          >true</literal> | <literal>on</literal> | <literal
170
 
          >0</literal> | <literal>no</literal> | <literal
171
 
          >false</literal> | <literal>off</literal> }</option></term>
172
 
        <listitem>
173
 
          <xi:include href="mandos-options.xml" xpointer="restore"/>
174
 
        </listitem>
175
 
      </varlistentry>
176
 
      
177
 
      <varlistentry>
178
 
        <term><option>statedir<literal> = </literal><replaceable
179
 
        >DIRECTORY</replaceable></option></term>
180
 
        <listitem>
181
 
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
182
 
        </listitem>
183
 
      </varlistentry>
184
 
      
185
 
      <varlistentry>
186
 
        <term><option>socket<literal> = </literal><replaceable
187
 
        >NUMBER</replaceable></option></term>
188
 
        <listitem>
189
 
          <xi:include href="mandos-options.xml" xpointer="socket"/>
190
 
        </listitem>
191
 
      </varlistentry>
192
 
      
193
166
    </variablelist>
194
167
  </refsect1>
195
168
  
205
178
    <para>
206
179
      The <literal>[DEFAULT]</literal> is necessary because the Python
207
180
      built-in module <systemitem class="library">ConfigParser</systemitem>
208
 
      requires it.
 
181
      requres it.
209
182
    </para>
210
 
    <xi:include href="bugs.xml"/>
211
183
  </refsect1>
212
184
  
213
185
  <refsect1 id="example">
227
199
      <programlisting>
228
200
[DEFAULT]
229
201
# A configuration example
230
 
interface = enp1s0
231
 
address = fe80::aede:48ff:fe71:f6f2
 
202
interface = eth0
 
203
address = 2001:db8:f983:bd0b:30de:ae4a:71f2:f672
232
204
port = 1025
233
 
debug = True
234
 
priority = SECURE128:!CTYPE-X.509:+CTYPE-RAWPK:!RSA:!VERS-ALL:+VERS-TLS1.3:%PROFILE_ULTRA
 
205
debug = true
 
206
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
235
207
servicename = Daena
236
 
use_dbus = False
237
 
use_ipv6 = True
238
 
restore = True
239
 
statedir = /var/lib/mandos
240
208
      </programlisting>
241
209
    </informalexample>
242
210
  </refsect1>
244
212
  <refsect1 id="see_also">
245
213
    <title>SEE ALSO</title>
246
214
    <para>
247
 
      <citerefentry><refentrytitle>intro</refentrytitle>
248
 
      <manvolnum>8mandos</manvolnum></citerefentry>,
249
 
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
250
 
      ><manvolnum>3</manvolnum></citerefentry>,
251
 
      <citerefentry><refentrytitle>mandos</refentrytitle>
252
 
      <manvolnum>8</manvolnum></citerefentry>,
253
 
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
254
 
      <manvolnum>5</manvolnum></citerefentry>
 
215
      <citerefentry>
 
216
        <refentrytitle>mandos</refentrytitle>
 
217
        <manvolnum>8</manvolnum></citerefentry>, <citerefentry>
 
218
        <refentrytitle>mandos-clients.conf</refentrytitle>
 
219
        <manvolnum>5</manvolnum></citerefentry>, <citerefentry>
 
220
        <refentrytitle>gnutls_priority_init</refentrytitle>
 
221
        <manvolnum>3</manvolnum></citerefentry>
255
222
    </para>
256
 
    
 
223
 
257
224
    <variablelist>
258
225
      <varlistentry>
259
226
        <term>
279
246
              <para>
280
247
                The clients use IPv6 link-local addresses, which are
281
248
                immediately usable since a link-local addresses is
282
 
                automatically assigned to a network interface when it
 
249
                automatically assigned to a network interfaces when it
283
250
                is brought up.
284
251
              </para>
285
252
            </listitem>
301
268
    </variablelist>
302
269
  </refsect1>
303
270
</refentry>
304
 
<!-- Local Variables: -->
305
 
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
306
 
<!-- time-stamp-end: "[\"']>" -->
307
 
<!-- time-stamp-format: "%:y-%02m-%02d" -->
308
 
<!-- End: -->