3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY CONFNAME "mandos-clients.conf">
5
5
<!ENTITY CONFPATH "<filename>/etc/mandos/clients.conf</filename>">
6
<!ENTITY TIMESTAMP "2012-05-12">
6
<!ENTITY TIMESTAMP "2010-09-26">
7
7
<!ENTITY % common SYSTEM "common.ent">
20
20
<firstname>Björn</firstname>
21
21
<surname>Påhlsson</surname>
23
<email>belorn@recompile.se</email>
23
<email>belorn@fukt.bsnet.se</email>
27
27
<firstname>Teddy</firstname>
28
28
<surname>Hogeborn</surname>
30
<email>teddy@recompile.se</email>
30
<email>teddy@fukt.bsnet.se</email>
66
64
><refentrytitle>mandos</refentrytitle>
67
65
<manvolnum>8</manvolnum></citerefentry>, read by it at startup.
68
66
The file needs to list all clients that should be able to use
69
the service. The settings in this file can be overridden by
70
runtime changes to the server, which it saves across restarts.
71
(See the section called <quote>PERSISTENT STATE</quote> in
72
<citerefentry><refentrytitle>mandos</refentrytitle><manvolnum
73
>8</manvolnum></citerefentry>.) However, any <emphasis
74
>changes</emphasis> to this file (including adding and removing
75
clients) will, at startup, override changes done during runtime.
67
the service. All clients listed will be regarded as enabled,
68
even if a client was disabled in a previous run of the server.
78
71
The format starts with a <literal>[<replaceable>section
191
<term><option>extended_timeout<literal> = </literal><replaceable
192
>TIME</replaceable></option></term>
195
This option is <emphasis>optional</emphasis>.
198
Extended timeout is an added timeout that is given once
199
after a password has been sent successfully to a client.
200
The timeout is by default longer than the normal timeout,
201
and is used for handling the extra long downtime while a
202
machine is booting up. Time to take into consideration
203
when changing this value is file system checks and quota
204
checks. The default value is 15 minutes.
207
The format of <replaceable>TIME</replaceable> is the same
208
as for <varname>timeout</varname> below.
214
184
<term><option>fingerprint<literal> = </literal
215
185
><replaceable>HEXSTRING</replaceable></option></term>
258
228
will wait for a checker to complete until the below
259
229
<quote><varname>timeout</varname></quote> occurs, at which
260
230
time the client will be disabled, and any running checker
261
killed. The default interval is 2 minutes.
231
killed. The default interval is 5 minutes.
264
234
The format of <replaceable>TIME</replaceable> is the same
328
298
This option is <emphasis>optional</emphasis>.
331
The timeout is how long the server will wait, after a
332
successful checker run, until a client is disabled and not
333
allowed to get the data this server holds. By default
334
Mandos will use 5 minutes. See also the
335
<option>extended_timeout</option> option.
301
The timeout is how long the server will wait (for either a
302
successful checker run or a client receiving its secret)
303
until a client is disabled and not allowed to get the data
304
this server holds. By default Mandos will use 1 hour.
338
307
The <replaceable>TIME</replaceable> is specified as a
354
<term><option>enabled<literal> = </literal>{ <literal
355
>1</literal> | <literal>yes</literal> | <literal>true</literal
356
> | <literal >on</literal> | <literal>0</literal> | <literal
357
>no</literal> | <literal>false</literal> | <literal
358
>off</literal> }</option></term>
361
Whether this client should be enabled by default. The
362
default is <quote>true</quote>.
402
357
<quote><literal>%%(<replaceable>foo</replaceable>)s</literal
403
358
></quote> will be replaced by the value of the attribute
404
359
<varname>foo</varname> of the internal
405
<quote><classname>Client</classname></quote> object in the
406
Mandos server. The currently allowed values for
407
<replaceable>foo</replaceable> are:
408
<quote><literal>approval_delay</literal></quote>,
409
<quote><literal>approval_duration</literal></quote>,
410
<quote><literal>created</literal></quote>,
411
<quote><literal>enabled</literal></quote>,
412
<quote><literal>expires</literal></quote>,
413
<quote><literal>fingerprint</literal></quote>,
414
<quote><literal>host</literal></quote>,
415
<quote><literal>interval</literal></quote>,
416
<quote><literal>last_approval_request</literal></quote>,
417
<quote><literal>last_checked_ok</literal></quote>,
418
<quote><literal>last_enabled</literal></quote>,
419
<quote><literal>name</literal></quote>,
420
<quote><literal>timeout</literal></quote>, and, if using
421
D-Bus, <quote><literal>dbus_object_path</literal></quote>.
422
See the source code for details. <emphasis role="strong"
423
>Currently, <emphasis>none</emphasis> of these attributes
424
except <quote><literal>host</literal></quote> are guaranteed
425
to be valid in future versions.</emphasis> Therefore, please
426
let the authors know of any attributes that are useful so they
427
may be preserved to any new versions of this software.
360
<quote><classname>Client</classname></quote> object. See the
361
source code for details, and let the authors know of any
362
attributes that are useful so they may be preserved to any new
363
versions of this software.
430
366
Note that this means that, in order to include an actual
505
441
<refsect1 id="see_also">
506
442
<title>SEE ALSO</title>
508
<citerefentry><refentrytitle>intro</refentrytitle>
509
<manvolnum>8mandos</manvolnum></citerefentry>,
510
444
<citerefentry><refentrytitle>mandos-keygen</refentrytitle>
511
445
<manvolnum>8</manvolnum></citerefentry>,
512
446
<citerefentry><refentrytitle>mandos.conf</refentrytitle>