/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2011-12-31 20:07:11 UTC
  • mfrom: (535.1.9 wireless-network-hook)
  • Revision ID: teddy@recompile.se-20111231200711-6dli3r8drftem57r
Merge new wireless network hook.  Fix bridge network hook to use
hardware addresses instead of interface names.  Implement and document
new "CONNECT" environment variable for network hooks.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version='1.0' encoding='UTF-8'?>
 
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY CONFNAME "mandos.conf">
6
5
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
7
 
<!ENTITY TIMESTAMP "2008-08-29">
 
6
<!ENTITY TIMESTAMP "2011-11-26">
 
7
<!ENTITY % common SYSTEM "common.ent">
 
8
%common;
8
9
]>
9
10
 
10
11
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
13
    <title>Mandos Manual</title>
13
14
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
15
    <productname>Mandos</productname>
15
 
    <productnumber>&VERSION;</productnumber>
 
16
    <productnumber>&version;</productnumber>
16
17
    <date>&TIMESTAMP;</date>
17
18
    <authorgroup>
18
19
      <author>
19
20
        <firstname>Björn</firstname>
20
21
        <surname>Påhlsson</surname>
21
22
        <address>
22
 
          <email>belorn@fukt.bsnet.se</email>
 
23
          <email>belorn@recompile.se</email>
23
24
        </address>
24
25
      </author>
25
26
      <author>
26
27
        <firstname>Teddy</firstname>
27
28
        <surname>Hogeborn</surname>
28
29
        <address>
29
 
          <email>teddy@fukt.bsnet.se</email>
 
30
          <email>teddy@recompile.se</email>
30
31
        </address>
31
32
      </author>
32
33
    </authorgroup>
33
34
    <copyright>
34
35
      <year>2008</year>
 
36
      <year>2009</year>
 
37
      <year>2011</year>
35
38
      <holder>Teddy Hogeborn</holder>
36
39
      <holder>Björn Påhlsson</holder>
37
40
    </copyright>
38
 
    <legalnotice>
39
 
      <para>
40
 
        This manual page is free software: you can redistribute it
41
 
        and/or modify it under the terms of the GNU General Public
42
 
        License as published by the Free Software Foundation,
43
 
        either version 3 of the License, or (at your option) any
44
 
        later version.
45
 
      </para>
46
 
 
47
 
      <para>
48
 
        This manual page is distributed in the hope that it will
49
 
        be useful, but WITHOUT ANY WARRANTY; without even the
50
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
51
 
        PARTICULAR PURPOSE.  See the GNU General Public License
52
 
        for more details.
53
 
      </para>
54
 
 
55
 
      <para>
56
 
        You should have received a copy of the GNU General Public
57
 
        License along with this program; If not, see
58
 
        <ulink url="http://www.gnu.org/licenses/"/>.
59
 
      </para>
60
 
    </legalnotice>
 
41
    <xi:include href="legalnotice.xml"/>
61
42
  </refentryinfo>
62
 
 
 
43
  
63
44
  <refmeta>
64
45
    <refentrytitle>&CONFNAME;</refentrytitle>
65
46
    <manvolnum>5</manvolnum>
71
52
      Configuration file for the Mandos server
72
53
    </refpurpose>
73
54
  </refnamediv>
74
 
 
 
55
  
75
56
  <refsynopsisdiv>
76
 
    <synopsis>
77
 
      &CONFPATH;
78
 
    </synopsis>
 
57
    <synopsis>&CONFPATH;</synopsis>
79
58
  </refsynopsisdiv>
80
 
 
 
59
  
81
60
  <refsect1 id="description">
82
61
    <title>DESCRIPTION</title>
83
62
    <para>
95
74
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
96
75
      to provide comments.
97
76
    </para>
98
 
 
 
77
    
99
78
  </refsect1>
100
79
  <refsect1>
101
80
    <title>OPTIONS</title>
102
81
    
103
82
    <variablelist>
104
83
      <varlistentry>
105
 
        <term><varname>interface</varname></term>
 
84
        <term><option>interface<literal> = </literal><replaceable
 
85
        >NAME</replaceable></option></term>
106
86
        <listitem>
107
 
          <synopsis><literal>interface = </literal><replaceable
108
 
          >NAME</replaceable>
109
 
          </synopsis>
110
87
          <xi:include href="mandos-options.xml" xpointer="interface"/>
111
88
        </listitem>
112
89
      </varlistentry>
113
 
 
 
90
      
114
91
      <varlistentry>
115
 
        <term><varname>address</varname></term>
 
92
        <term><option>address<literal> = </literal><replaceable
 
93
          >ADDRESS</replaceable></option></term>
116
94
        <listitem>
117
 
          <synopsis><literal>address = </literal><replaceable
118
 
          >ADDRESS</replaceable>
119
 
          </synopsis>
120
95
          <xi:include href="mandos-options.xml" xpointer="address"/>
121
96
        </listitem>
122
97
      </varlistentry>
123
 
 
 
98
      
124
99
      <varlistentry>
125
 
        <term><varname>port</varname></term>
 
100
        <term><option>port<literal> = </literal><replaceable
 
101
        >NUMBER</replaceable></option></term>
126
102
        <listitem>
127
 
          <synopsis><literal>port = </literal><replaceable
128
 
          >NUMBER</replaceable>
129
 
          </synopsis>
130
103
          <xi:include href="mandos-options.xml" xpointer="port"/>
131
104
        </listitem>
132
105
      </varlistentry>
133
 
 
 
106
      
134
107
      <varlistentry>
135
 
        <term><varname>debug</varname></term>
136
 
        <listitem>
137
 
          <synopsis><literal>debug = </literal>{ <literal
 
108
        <term><option>debug<literal> = </literal>{ <literal
138
109
          >1</literal> | <literal>yes</literal> | <literal
139
110
          >true</literal> | <literal>on</literal> | <literal
140
111
          >0</literal> | <literal>no</literal> | <literal
141
 
          >false</literal> | <literal>off</literal> }
142
 
          </synopsis>
 
112
          >false</literal> | <literal>off</literal> }</option></term>
 
113
        <listitem>
143
114
          <xi:include href="mandos-options.xml" xpointer="debug"/>
144
115
        </listitem>
145
116
      </varlistentry>
146
 
 
 
117
      
147
118
      <varlistentry>
148
 
        <term><varname>priority</varname></term>
 
119
        <term><option>priority<literal> = </literal><replaceable
 
120
        >STRING</replaceable></option></term>
149
121
        <listitem>
150
 
          <synopsis><literal>priority = </literal><replaceable
151
 
          >STRING</replaceable>
152
 
          </synopsis>
153
122
          <xi:include href="mandos-options.xml" xpointer="priority"/>
154
123
        </listitem>
155
124
      </varlistentry>
156
 
 
 
125
      
157
126
      <varlistentry>
158
 
        <term><varname>servicename</varname></term>
 
127
        <term><option>servicename<literal> = </literal
 
128
        ><replaceable>NAME</replaceable></option></term>
159
129
        <listitem>
160
 
          <synopsis><literal>servicename = </literal><replaceable
161
 
          >NAME</replaceable>
162
 
          </synopsis>
163
130
          <xi:include href="mandos-options.xml"
164
131
                      xpointer="servicename"/>
165
132
        </listitem>
166
133
      </varlistentry>
167
134
      
 
135
      <varlistentry>
 
136
        <term><option>use_dbus<literal> = </literal>{ <literal
 
137
          >1</literal> | <literal>yes</literal> | <literal
 
138
          >true</literal> | <literal>on</literal> | <literal
 
139
          >0</literal> | <literal>no</literal> | <literal
 
140
          >false</literal> | <literal>off</literal> }</option></term>
 
141
        <listitem>
 
142
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
 
143
        </listitem>
 
144
      </varlistentry>
 
145
      
 
146
      <varlistentry>
 
147
        <term><option>use_ipv6<literal> = </literal>{ <literal
 
148
          >1</literal> | <literal>yes</literal> | <literal
 
149
          >true</literal> | <literal>on</literal> | <literal
 
150
          >0</literal> | <literal>no</literal> | <literal
 
151
          >false</literal> | <literal>off</literal> }</option></term>
 
152
        <listitem>
 
153
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
 
154
        </listitem>
 
155
      </varlistentry>
 
156
      
 
157
      <varlistentry>
 
158
        <term><option>restore<literal> = </literal>{ <literal
 
159
          >1</literal> | <literal>yes</literal> | <literal
 
160
          >true</literal> | <literal>on</literal> | <literal
 
161
          >0</literal> | <literal>no</literal> | <literal
 
162
          >false</literal> | <literal>off</literal> }</option></term>
 
163
        <listitem>
 
164
          <xi:include href="mandos-options.xml" xpointer="restore"/>
 
165
        </listitem>
 
166
      </varlistentry>
 
167
      
 
168
      <varlistentry>
 
169
        <term><option>statedir<literal> = </literal><replaceable
 
170
        >DIRECTORY</replaceable></option></term>
 
171
        <listitem>
 
172
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
 
173
        </listitem>
 
174
      </varlistentry>
 
175
      
168
176
    </variablelist>
169
177
  </refsect1>
170
178
  
180
188
    <para>
181
189
      The <literal>[DEFAULT]</literal> is necessary because the Python
182
190
      built-in module <systemitem class="library">ConfigParser</systemitem>
183
 
      requres it.
 
191
      requires it.
184
192
    </para>
185
193
  </refsect1>
186
194
  
202
210
[DEFAULT]
203
211
# A configuration example
204
212
interface = eth0
205
 
address = 2001:db8:f983:bd0b:30de:ae4a:71f2:f672
 
213
address = fe80::aede:48ff:fe71:f6f2
206
214
port = 1025
207
215
debug = true
208
216
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
209
217
servicename = Daena
 
218
use_dbus = False
 
219
use_ipv6 = True
 
220
restore = True
 
221
statedir = /var/lib/mandos
210
222
      </programlisting>
211
223
    </informalexample>
212
224
  </refsect1>
214
226
  <refsect1 id="see_also">
215
227
    <title>SEE ALSO</title>
216
228
    <para>
 
229
      <citerefentry><refentrytitle>intro</refentrytitle>
 
230
      <manvolnum>8mandos</manvolnum></citerefentry>,
217
231
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
218
232
      ><manvolnum>3</manvolnum></citerefentry>,
219
233
      <citerefentry><refentrytitle>mandos</refentrytitle>
221
235
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
222
236
      <manvolnum>5</manvolnum></citerefentry>
223
237
    </para>
224
 
 
 
238
    
225
239
    <variablelist>
226
240
      <varlistentry>
227
241
        <term>
247
261
              <para>
248
262
                The clients use IPv6 link-local addresses, which are
249
263
                immediately usable since a link-local addresses is
250
 
                automatically assigned to a network interfaces when it
 
264
                automatically assigned to a network interface when it
251
265
                is brought up.
252
266
              </para>
253
267
            </listitem>