1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
<!ENTITY VERSION "1.0">
4
5
<!ENTITY COMMANDNAME "mandos-client">
5
<!ENTITY TIMESTAMP "2009-01-24">
6
<!ENTITY % common SYSTEM "../common.ent">
6
<!ENTITY TIMESTAMP "2008-09-06">
10
9
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
11
<title>Mandos Manual</title>
13
<!-- NWalsh’s docbook scripts use this to generate the footer: -->
12
<!-- Nwalsh’s docbook scripts use this to generate the footer: -->
14
13
<productname>Mandos</productname>
15
<productnumber>&version;</productnumber>
14
<productnumber>&VERSION;</productnumber>
16
15
<date>&TIMESTAMP;</date>
36
34
<holder>Teddy Hogeborn</holder>
37
35
<holder>Björn Påhlsson</holder>
39
37
<xi:include href="../legalnotice.xml"/>
43
41
<refentrytitle>&COMMANDNAME;</refentrytitle>
44
42
<manvolnum>8mandos</manvolnum>
117
115
</refsynopsisdiv>
119
117
<refsect1 id="description">
120
118
<title>DESCRIPTION</title>
122
120
<command>&COMMANDNAME;</command> is a client program that
123
121
communicates with <citerefentry><refentrytitle
124
122
>mandos</refentrytitle><manvolnum>8</manvolnum></citerefentry>
125
to get a password. In slightly more detail, this client program
126
brings up a network interface, uses the interface’s IPv6
127
link-local address to get network connectivity, uses Zeroconf to
128
find servers on the local network, and communicates with servers
129
using TLS with an OpenPGP key to ensure authenticity and
130
confidentiality. This client program keeps running, trying all
131
servers on the network, until it receives a satisfactory reply
132
or a TERM signal is received. If no servers are found, or after
133
all servers have been tried, it waits indefinitely for new
123
to get a password. It uses IPv6 link-local addresses to get
124
network connectivity, Zeroconf to find servers, and TLS with an
125
OpenPGP key to ensure authenticity and confidentiality. It
126
keeps running, trying all servers on the network, until it
127
receives a satisfactory reply or a TERM signal is received.
137
130
This program is not meant to be run directly; it is really meant
206
199
specifies the interface to use to connect to the address
210
Note that since this program will normally run in the
211
initial RAM disk environment, the interface must be an
212
interface which exists at that stage. Thus, the interface
213
can not be a pseudo-interface such as <quote>br0</quote>
214
or <quote>tun0</quote>; such interfaces will not exist
215
until much later in the boot process, and can not be used
465
449
The only remaining weak point is that someone with physical
466
450
access to the client hard drive might turn off the client
467
451
computer, read the OpenPGP keys directly from the hard drive,
468
and communicate with the server. To safeguard against this, the
469
server is supposed to notice the client disappearing and stop
470
giving out the encrypted data. Therefore, it is important to
471
set the timeout and checker interval values tightly on the
472
server. See <citerefentry><refentrytitle
452
and communicate with the server. The defense against this is
453
that the server is supposed to notice the client disappearing
454
and will stop giving out the encrypted data. Therefore, it is
455
important to set the timeout and checker interval values tightly
456
on the server. See <citerefentry><refentrytitle
473
457
>mandos</refentrytitle><manvolnum>8</manvolnum></citerefentry>.