/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to plugins.d/mandos-client.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-07-01 20:01:26 UTC
  • mto: This revision was merged to the branch mainline in revision 759.
  • Revision ID: teddy@recompile.se-20150701200126-qb3f6c3jcas2f4og
mandos-client: Try to start a plugin to add and remove a local route.

* debian/mandos-client.README.Debian: Add setting of environment
                                      variable MANDOSPLUGINHELPERDIR
                                      to command line testing
                                      mandos-client.
* mandos-client.c (raise_privileges): Moved to top of file.
                  (raise_privileges_permanently): - '' -
                  (lower_privileges): - '' -
                  (lower_privileges_permanently): - '' -
  (add_remove_local_route, add_local_route, remove_local_route): New.
  (start_mandos_communication): Set SOCK_CLOEXEC flag on socket.  Run
                                the above functions to add (and
                                remove) local route, if the conditions
                                indicates it could help.
  (run_network_hooks): Use O_DIRECTORY, O_PATH, and O_CLOEXEC flags
                       when opening network hook directory. Do
                       TEMP_FAILURE_RETRY around opening of /dev/null
                       and network hook executables.  Move redirecting
                       of stdout and stderr to as late as possible
                       before fexecve().
  (main): Use O_DIRECTORY and O_PATH when opening temporary directory.
* plugins.d/mandos-client.xml (ENVIRONMENT): Document usage of the
                                             MANDOSPLUGINHELPERDIR
                                             environment variable.

Show diffs side-by-side

added added

removed removed

Lines of Context:
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY COMMANDNAME "mandos-client">
5
 
<!ENTITY TIMESTAMP "2017-02-23">
 
5
<!ENTITY TIMESTAMP "2015-06-29">
6
6
<!ENTITY % common SYSTEM "../common.ent">
7
7
%common;
8
8
]>
33
33
    <copyright>
34
34
      <year>2008</year>
35
35
      <year>2009</year>
36
 
      <year>2010</year>
37
 
      <year>2011</year>
38
36
      <year>2012</year>
39
37
      <year>2013</year>
40
38
      <year>2014</year>
41
39
      <year>2015</year>
42
 
      <year>2016</year>
43
 
      <year>2017</year>
44
40
      <holder>Teddy Hogeborn</holder>
45
41
      <holder>Björn Påhlsson</holder>
46
42
    </copyright>
103
99
      </arg>
104
100
      <sbr/>
105
101
      <arg>
106
 
        <option>--dh-params <replaceable>FILE</replaceable></option>
107
 
      </arg>
108
 
      <sbr/>
109
 
      <arg>
110
102
        <option>--delay <replaceable>SECONDS</replaceable></option>
111
103
      </arg>
112
104
      <sbr/>
320
312
        <listitem>
321
313
          <para>
322
314
            Sets the number of bits to use for the prime number in the
323
 
            TLS Diffie-Hellman key exchange.  The default value is
324
 
            selected automatically based on the OpenPGP key.  Note
325
 
            that if the <option>--dh-params</option> option is used,
326
 
            the values from that file will be used instead.
327
 
          </para>
328
 
        </listitem>
329
 
      </varlistentry>
330
 
      
331
 
      <varlistentry>
332
 
        <term><option>--dh-params=<replaceable
333
 
        >FILE</replaceable></option></term>
334
 
        <listitem>
335
 
          <para>
336
 
            Specifies a PEM-encoded PKCS#3 file to read the parameters
337
 
            needed by the TLS Diffie-Hellman key exchange from.  If
338
 
            this option is not given, or if the file for some reason
339
 
            could not be used, the parameters will be generated on
340
 
            startup, which will take some time and processing power.
341
 
            Those using servers running under time, power or processor
342
 
            constraints may want to generate such a file in advance
343
 
            and use this option.
 
315
            TLS Diffie-Hellman key exchange.  Default is 1024.
344
316
          </para>
345
317
        </listitem>
346
318
      </varlistentry>
694
666
    </variablelist>
695
667
  </refsect1>
696
668
  
697
 
  <refsect1 id="bugs">
698
 
    <title>BUGS</title>
699
 
    <xi:include href="../bugs.xml"/>
700
 
  </refsect1>
 
669
<!--   <refsect1 id="bugs"> -->
 
670
<!--     <title>BUGS</title> -->
 
671
<!--     <para> -->
 
672
<!--     </para> -->
 
673
<!--   </refsect1> -->
701
674
  
702
675
  <refsect1 id="example">
703
676
    <title>EXAMPLE</title>
843
816
      </varlistentry>
844
817
      <varlistentry>
845
818
        <term>
846
 
          <ulink url="https://www.gnutls.org/">GnuTLS</ulink>
 
819
          <ulink url="http://www.gnu.org/software/gnutls/"
 
820
          >GnuTLS</ulink>
847
821
        </term>
848
822
      <listitem>
849
823
        <para>
855
829
      </varlistentry>
856
830
      <varlistentry>
857
831
        <term>
858
 
          <ulink url="https://www.gnupg.org/related_software/gpgme/"
 
832
          <ulink url="http://www.gnupg.org/related_software/gpgme/"
859
833
                 >GPGME</ulink>
860
834
        </term>
861
835
        <listitem>
899
873
      </varlistentry>
900
874
      <varlistentry>
901
875
        <term>
902
 
          RFC 5246: <citetitle>The Transport Layer Security (TLS)
903
 
          Protocol Version 1.2</citetitle>
 
876
          RFC 4346: <citetitle>The Transport Layer Security (TLS)
 
877
          Protocol Version 1.1</citetitle>
904
878
        </term>
905
879
      <listitem>
906
880
        <para>
907
 
          TLS 1.2 is the protocol implemented by GnuTLS.
 
881
          TLS 1.1 is the protocol implemented by GnuTLS.
908
882
        </para>
909
883
      </listitem>
910
884
      </varlistentry>
921
895
      </varlistentry>
922
896
      <varlistentry>
923
897
        <term>
924
 
          RFC 6091: <citetitle>Using OpenPGP Keys for Transport Layer
 
898
          RFC 5081: <citetitle>Using OpenPGP Keys for Transport Layer
925
899
          Security</citetitle>
926
900
        </term>
927
901
      <listitem>