/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to intro.xml

  • Committer: Teddy Hogeborn
  • Date: 2019-07-18 00:02:43 UTC
  • Revision ID: teddy@recompile.se-20190718000243-okz4s9xao1r1tfnx
Document bug in mandos-keygen which strips white space from passwords

Passwords, as read by mandos-keygen when given the --password or -p
options, are stripped of white space from the start and from the end
of the password.  This is because mandos-keygen is a shell script, and
the Bourne Shell "read" builtin does not seem to have a way to avoid
this.  Document this bug.

* manods-keygen.xml (OPTIONS): Document the white space-stripping
                               nature of the --password/-p option, and
                               also note in the description of
                               --passfile and -F that they avoid this
                               behavior.
  (BUGS): Again mention the problem with the --password and -p
          options, and suggest --passfile as a possible workaround.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY TIMESTAMP "2021-02-03">
 
4
<!ENTITY TIMESTAMP "2019-04-10">
5
5
<!ENTITY % common SYSTEM "common.ent">
6
6
%common;
7
7
]>
39
39
      <year>2017</year>
40
40
      <year>2018</year>
41
41
      <year>2019</year>
42
 
      <year>2020</year>
43
42
      <holder>Teddy Hogeborn</holder>
44
43
      <holder>Björn Påhlsson</holder>
45
44
    </copyright>
385
384
      plugin requirements.
386
385
    </para>
387
386
  </refsect1>
388
 
 
389
 
  <refsect1 id="systemd">
390
 
    <title>SYSTEMD</title>
391
 
    <para>
392
 
      More advanced startup systems like <citerefentry><refentrytitle
393
 
      >systemd</refentrytitle><manvolnum>1</manvolnum></citerefentry>,
394
 
      already have their own plugin-like mechanisms for allowing
395
 
      multiple agents to independently retrieve a password and deliver
396
 
      it to the subsystem requesting a password to unlock the root
397
 
      file system.  On these systems, it would make no sense to run
398
 
      <citerefentry><refentrytitle>plugin-runner</refentrytitle
399
 
      ><manvolnum>8mandos</manvolnum></citerefentry>, the plugins of
400
 
      which would largely duplicate the work of (and conflict with)
401
 
      the existing systems prompting for passwords.
402
 
    </para>
403
 
    <para>
404
 
      As for <citerefentry><refentrytitle>systemd</refentrytitle
405
 
      ><manvolnum>1</manvolnum></citerefentry> in particular, it has
406
 
      its own <ulink
407
 
      url="https://systemd.io/PASSWORD_AGENTS/">Password
408
 
      Agents</ulink> system.  Mandos uses this via its
409
 
      <citerefentry><refentrytitle>password-agent</refentrytitle
410
 
      ><manvolnum>8mandos</manvolnum></citerefentry> program, which is
411
 
      run instead of <citerefentry><refentrytitle
412
 
      >plugin-runner</refentrytitle><manvolnum>8mandos</manvolnum
413
 
      ></citerefentry> when <citerefentry><refentrytitle
414
 
      >systemd</refentrytitle><manvolnum>1</manvolnum></citerefentry>
415
 
      is used during system startup.
416
 
    </para>
417
 
  </refsect1>
 
387
  
418
388
  <refsect1 id="bugs">
419
389
    <title>BUGS</title>
420
390
    <xi:include href="bugs.xml"/>
435
405
      <manvolnum>8</manvolnum></citerefentry>,
436
406
      <citerefentry><refentrytitle>plugin-runner</refentrytitle>
437
407
      <manvolnum>8mandos</manvolnum></citerefentry>,
438
 
      <citerefentry><refentrytitle>password-agent</refentrytitle>
439
 
      <manvolnum>8mandos</manvolnum></citerefentry>,
440
408
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
441
409
      <manvolnum>8mandos</manvolnum></citerefentry>,
442
410
      <citerefentry><refentrytitle>password-prompt</refentrytitle>