7
** [[https://www.freedesktop.org/software/polkit/docs/latest/polkit-apps.html][Writing polkit applications]]
10
** TODO A ~--server~ option which only adds to the server list.
11
(Unlike ~--connect~, which implicitly disables ZeroConf.)
12
** TODO [#B] Use [[man:capabilities][capabilities]] instead of [[info:libc#Setting%20User%20ID][seteuid()]].
13
[[https://forums.grsecurity.net/viewtopic.php?f=7&t=2522]]
14
** TODO [#B] Use ~getaddrinfo(hints=AI_NUMERICHOST)~ instead of ~inet_pton()~
15
** TODO [#C] Make ~start_mandos_communication()~ take ~struct server~.
16
** TODO [#C] ~--interfaces=regex,eth*,noregex~ [[man:bridge-utils-interfaces][bridge-utils-interfaces(5)]]
17
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
20
** TODO [#B] use [[info:libc#Scanning%20Directory%20Content][scandir(3)]] instead of [[info:libc#Reading/Closing%20Directory][readdir(3)]]
21
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
23
* usplash (Deprecated)
24
** TODO [#B] Make it work again
25
** TODO [#B] use [[info:libc#Scanning%20Directory%20Content][scandir(3)]] instead of [[info:libc#Reading/Closing%20Directory][readdir(3)]]
26
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
29
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
32
** TODO [#B] lock stdin (with [[info:libc#File%20Locks][flock()]]?)
33
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
36
** TODO [#A] Detect partial writes to stdout and exit with ~EX_TEMPFAIL~
6
** [#B] Add more comments to code
7
** [#B] Add more if(debug) calls
8
** [#B] Seperate more code to function for more readability
9
** [#A] Man page: man8/plugin-runner.8mandos
12
Examples of normal usage, debug usage, debugging single or all
16
Note the danger of using this program, since you might lock
17
yourself out of your system without any means of entering the root
18
file system password. This is, however, very unlikely considering
19
the fallback to getpass(3).
22
Explaining text on what you can read
25
** [#A] Man page: man8/password-request.8mandos
27
Document short options
29
State that this command is not meant to be invoked directly, but
30
is run as a plugin from mandos-client(8) and only run in the
31
initrd environment, not the real system.
38
Note that it does *not* currently use cryptsource or crypttarget.
40
Describe the key files and the key ring files. Also note that
41
they should normally have been automatically created.
44
Examples of normal usage, debug usage, debugging by connecting
48
Update from mandos.xml
49
** [#B] Temporarily lower kernel log level
50
for less printouts during sucessfull boot.
52
** use strsep instead of strtok?
53
** Do not depend on GnuPG key rings on disk
54
This would mean creating new GnuPG key rings with GPGME by
55
importing the key files from scratch on every program start.
56
** Keydir move: /etc/mandos -> /etc/keys/mandos
57
Must create in preinst if not pre-depending on cryptsetup
60
** [#A] Man page: man8/password-prompt.8mandos
62
Document short options
64
Note that this is more or less a simple getpass(3) wrapper, even
65
though actual use of getpass(3) is not guaranteed.
68
Document use of "cryptsource" and "crypttarget".
72
Examples of normal usage, debug usage, with a prefix, etc.
74
Not much to do here but it is noteworthy to state the danger of
75
not having a fallback option.
77
Refer to mandos-client(8mandos) and password-request(8mandos)
78
and also, perhaps, to cryptsetup(8)?
80
Man page says "obsolete", but [[info:libc:getpass][GNU LibC Manual: Reading Passwords]]
81
does not. See also [[http://sources.redhat.com/ml/libc-alpha/2003-05/msg00251.html][Marcus Brinkmann: Re: getpass obsolete?]] and
82
[[http://article.gmane.org/gmane.comp.lib.glibc.alpha/4906][Petter Reinholdtsen: Re: getpass obsolete?]], and especially also
83
[[http://www.steve.org.uk/Reference/Unix/faq_4.html#SEC48][Unix Programming FAQ 3.1 How can I make my program not echo input?]]
41
** TODO handle printing for errors for plugins
42
*** Hook up stderr of plugins, buffer them, and prepend "Mandos Plugin [plugin name]"
43
** TODO [#C] use same file name rules as [[man:run-parts][run-parts(8)]]
44
** kernel command line option for debug info
45
** TODO [#A] Restart plugins which exit with ~EX_TEMPFAIL~
86
** [#A] Config file man page: man5/mandos.conf (mandos.conf)
87
** [#A] Config file man page: man5/mandos-clients.conf (clients.conf)
88
** [#A] /etc/init.d/mandos-server :teddy:
89
** [#B] Log level :bugs:
90
** /etc/mandos/clients.d/*.conf
91
Watch this directory and add/remove/update clients?
92
** config for TXT record
93
** [#B] Run-time communication with server :bugs:
95
See also [[*Mandos-tools]]
96
** Implement --foreground :bugs:
97
[[info:standards:Option%20Table][Table of Long Options]]
99
[[info:standards:Option%20Table][Table of Long Options]]
100
** Date+time on console log messages :bugs:
103
* Mandos-tools/utilities
104
All of this probably using D-Bus
111
*** Update initrd.img after installation
112
This seems to use some kind of "trigger" system
113
*** Keydir move: /etc/mandos -> /etc/keys/mandos
114
Must create in preinst if not pre-depending on cryptsetup
116
**** [#A] Output cut-and-paste ready snippet for clients.conf.
118
*** [#A] Create mandos user and group for server
119
*** [#A] Create /var/run/mandos directory with perm and ownership
48
** TODO [#B] ~--notify-command~
49
This would allow the mandos.service to use
50
~--notify-command="systemd-notify --pid --ready"~
51
** TODO [#B] python-systemd
52
*** import systemd.daemon; systemd.daemon.notify()
53
** TODO [#B] Log level :BUGS:
54
*** TODO /etc/mandos/clients.d/*.conf
55
Watch this directory and add/remove/update clients?
56
** TODO [#C] config for TXT record
57
** TODO Log level dbus option
58
SetLogLevel D-Bus call
59
** TODO [#C] DBusServiceObjectUsingSuper
60
** TODO [#B] Global enable/disable flag
61
** TODO [#B] By-client countdown on number of secrets given
62
** D-Bus Client method NeedsPassword(50) - Timeout, default disapprove
63
+ SetPass("gazonk", True) -> Approval, persistent
64
+ Approve(False) -> Close client connection immediately
65
** TODO [#C] python-parsedatetime
66
** TODO Separate logging logic to own object
67
** TODO [#B] Limit ~approval_delay~ to max GnuTLS/TLS timeout value
68
** TODO [#B] break the wait on ~approval_delay~ if connection dies
69
** TODO Generate ~Client.runtime_expansions~ from client options + extra
70
** TODO Allow %%(checker)s as a runtime expansion
71
** TODO D-Bus AddClient() method on server object
72
** TODO Use org.freedesktop.DBus.Method.NoReply annotation on async methods. :2:
73
** TODO Save state periodically to recover better from hard shutdowns
74
** TODO CheckerCompleted method, deprecate CheckedOK
75
** TODO [[https://standards.freedesktop.org/secret-service/][Secret Service]] API?
76
** TODO Remove D-Bus interfaces with old domain name :2:
77
** TODO Remove old ~string_to_delta~ format :2:
78
** TODO http://0pointer.de/blog/projects/stateless.html
79
*** File in /usr/lib/sysusers.d to create user+group "~_mandos~"
80
** TODO Error handling on error parsing config files
81
** TODO init.d script error handling
82
** TODO D-Bus server properties; address, port, interface, etc. :2:
85
** TODO Remove old string_to_delta format :2:
87
* TODO mandos-dispatch
88
Listens for specified D-Bus signals and spawns shell commands with
92
** TODO ~--servicename~ :BUGS:
93
** TODO help should be toggleable
94
** Urwid client data displayer
95
Better view of client data in the listing
97
** Print a nice "We are sorry" message, save stack trace to log.
100
** TODO "~--secfile~" option
101
Using the "secfile" option instead of "secret"
102
** TODO [#B] "~--test~" option
103
For testing decryption before rebooting.
122
106
** /usr/share/initramfs-tools/hooks/mandos
123
*** Do not install in initrd.img if configured not to.
124
Use "/etc/initramfs-tools/conf.d/mandos"? Definitely a debconf
126
** /etc/bash_completion.d/mandos
107
*** TODO [#C] use same file name rules as [[man:run-parts][run-parts(8)]]
108
*** TODO [#C] Do not install in initrd.img if configured not to.
109
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
110
** TODO [#C] ~$(pkg-config --variable=completionsdir bash-completion)~
127
111
From XML sources directly?
137
* Announce project on news
138
[[news:comp.os.linux.announce]]
114
** TODO Locate which package moves the other bin/sh when busybox is deactivated
115
** TODO contact owner of package, and ask them to have that shell static in position regardless of busybox
117
* [[http://www.undeadly.org/cgi?action=article&sid=20110530221728][OpenBSD]]
141
120
#+STARTUP: showall