4
** TODO [#B] use scandir(3) instead of readdir(3)
5
** TODO [#B] Prefix all debug output with argv[0]
6
** TODO [#B] Retry a server which has a non-definite reply:
7
*** A closed connection during the TLS handshake
9
** TODO [#B] Use capabilities instead of seteuid().
12
** TODO [#B] use scandir(3) instead of readdir(3)
13
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
16
** TODO [#B] use scandir(3) instead of readdir(3)
17
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
20
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
21
** TODO [#B] Drop privileges after opening FIFO.
6
** [#B] Temporarily lower kernel log level
7
for less printouts during sucessfull boot.
9
** use strsep instead of strtok?
10
** Do not depend on GnuPG key rings on disk
11
This would mean creating new GnuPG key rings with GPGME by
12
importing the key files from scratch on every program start.
13
** Keydir move: /etc/mandos -> /etc/keys/mandos
14
Must create in preinst if not pre-depending on cryptsetup
24
** TODO [#B] Prefix all debug output with "Mandos plugin " + argv[0]
29
** TODO [#B] use scandir(3) instead of readdir(3)
30
** TODO [#C] use same file name rules as run-parts(8)
33
** TODO [#B] Log level :BUGS:
34
** TODO /etc/mandos/clients.d/*.conf
19
** [#A] /etc/init.d/mandos-server :teddy:
20
** [#B] Log level :bugs:
21
** /etc/mandos/clients.d/*.conf
35
22
Watch this directory and add/remove/update clients?
36
** TODO config for TXT record
37
** TODO [#B] Run-time communication with server :BUGS:
23
** config for TXT record
24
** [#B] Run-time communication with server :bugs:
38
25
Probably using D-Bus
42
syslogger.setLevel(logging.WARNING)
43
+ [[http://log.ometer.com/2007-05.html][Best D-Bus practices]]
44
** TODO Implement --foreground :BUGS:
45
[[info:standards:Option%20Table][Table of Long Options]]
46
** TODO Implement --socket
47
[[info:standards:Option%20Table][Table of Long Options]]
48
** TODO Date+time on console log messages :BUGS:
26
See also [[*Mandos-tools]]
27
** Implement --foreground :bugs:
28
[[info:standards:Option%20Table][Table of Long Options]]
30
[[info:standards:Option%20Table][Table of Long Options]]
31
** Date+time on console log messages :bugs:
49
32
Is this the default?
50
** TODO DBusServiceObjectUsingSuper
51
** TODO Global enable/disable flag
52
** TODO By-client countdown on secrets given
53
** TODO Fix problem with fsck taking a really long time
54
Whenever a client successfully gets a secret it could get a
55
one-time timeout boost to allow for an fsck-incurred delay
56
** TODO Delay before client receives key
57
This would give an operator opportunity to cancel the request if
59
** TODO Client manual approval mode
60
A client needs manual approval on the server before it gets the
62
** TODO Persistent state
66
** [[file:mandos.xml::XXX][Document D-Bus interface]]
68
* Provide and install /etc/dbus-1/system.d/mandos.conf
71
*** Handle "no D-Bus server" and/or "no Mandos server found" better
72
*** [#B] --dump option
74
* TODO mandos-dispatch
75
Listens for specified D-Bus signals and spawns shell commands with
79
** D-Bus mail loop w/ signal receiver
80
** Snack/Newt client data displayer
85
** TODO Loop until passwords match when run interactively
86
** TODO "--secfile" option
87
Using the "secfile" option instead of "secret"
88
** TODO [#B] "--test" option
89
For testing decryption before rebooting.
92
** Implement DEB_BUILD_OPTIONS
93
http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
33
** delete hook when clients fall out by timeout
35
* Mandos-tools/utilities
36
All of this probably using D-Bus
43
** Use xinclude for common sections
49
*** Update initrd.img after installation
50
This seems to use some kind of "trigger" system
51
[[file:/usr/share/doc/dpkg/triggers.txt.gz]]
52
dpkg-trigger(1), deb-triggers(5)
53
*** Keydir move: /etc/mandos -> /etc/keys/mandos
54
Must create in preinst if not pre-depending on cryptsetup
56
**** "--passfile" option
57
Using the "secfile" option instead of "secret"
58
**** [#A] "--test" option
59
For testing decryption before rebooting.
61
*** [#A] Create mandos user and group for server
62
*** [#A] Create /var/run/mandos directory with perm and ownership
96
65
** /usr/share/initramfs-tools/hooks/mandos
97
*** TODO [#C] use same file name rules as run-parts(8)
98
*** TODO [#C] Do not install in initrd.img if configured not to.
99
Use "/etc/initramfs-tools/hooksconf.d/mandos"?
100
** TODO [#C] /etc/bash_completion.d/mandos
66
*** Do not install in initrd.img if configured not to.
67
Use "/etc/initramfs-tools/conf.d/mandos"? Definitely a debconf
69
** /etc/bash_completion.d/mandos
101
70
From XML sources directly?
80
* Announce project on news
81
[[news:comp.os.linux.announce]]
104
84
#+STARTUP: showall