/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-01-25 00:02:51 UTC
  • Revision ID: teddy@recompile.se-20150125000251-j2bw50gfq9smqyxe
mandos.xml (SEE ALSO): Update links.

Update link to GnuPG home page, change reference from TLS 1.1 to TLS
1.2, and change to latest RFC for using OpenPGP keys with TLS (and use
its correct title).

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY CONFNAME "mandos.conf">
6
5
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
7
 
<!ENTITY TIMESTAMP "2008-08-31">
 
6
<!ENTITY TIMESTAMP "2013-10-23">
 
7
<!ENTITY % common SYSTEM "common.ent">
 
8
%common;
8
9
]>
9
10
 
10
11
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
13
    <title>Mandos Manual</title>
13
14
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
15
    <productname>Mandos</productname>
15
 
    <productnumber>&VERSION;</productnumber>
 
16
    <productnumber>&version;</productnumber>
16
17
    <date>&TIMESTAMP;</date>
17
18
    <authorgroup>
18
19
      <author>
19
20
        <firstname>Björn</firstname>
20
21
        <surname>Påhlsson</surname>
21
22
        <address>
22
 
          <email>belorn@fukt.bsnet.se</email>
 
23
          <email>belorn@recompile.se</email>
23
24
        </address>
24
25
      </author>
25
26
      <author>
26
27
        <firstname>Teddy</firstname>
27
28
        <surname>Hogeborn</surname>
28
29
        <address>
29
 
          <email>teddy@fukt.bsnet.se</email>
 
30
          <email>teddy@recompile.se</email>
30
31
        </address>
31
32
      </author>
32
33
    </authorgroup>
33
34
    <copyright>
34
35
      <year>2008</year>
 
36
      <year>2009</year>
 
37
      <year>2011</year>
 
38
      <year>2012</year>
 
39
      <year>2013</year>
35
40
      <holder>Teddy Hogeborn</holder>
36
41
      <holder>Björn Påhlsson</holder>
37
42
    </copyright>
38
 
    <legalnotice>
39
 
      <para>
40
 
        This manual page is free software: you can redistribute it
41
 
        and/or modify it under the terms of the GNU General Public
42
 
        License as published by the Free Software Foundation,
43
 
        either version 3 of the License, or (at your option) any
44
 
        later version.
45
 
      </para>
46
 
 
47
 
      <para>
48
 
        This manual page is distributed in the hope that it will
49
 
        be useful, but WITHOUT ANY WARRANTY; without even the
50
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
51
 
        PARTICULAR PURPOSE.  See the GNU General Public License
52
 
        for more details.
53
 
      </para>
54
 
 
55
 
      <para>
56
 
        You should have received a copy of the GNU General Public
57
 
        License along with this program; If not, see
58
 
        <ulink url="http://www.gnu.org/licenses/"/>.
59
 
      </para>
60
 
    </legalnotice>
 
43
    <xi:include href="legalnotice.xml"/>
61
44
  </refentryinfo>
62
 
 
 
45
  
63
46
  <refmeta>
64
47
    <refentrytitle>&CONFNAME;</refentrytitle>
65
48
    <manvolnum>5</manvolnum>
71
54
      Configuration file for the Mandos server
72
55
    </refpurpose>
73
56
  </refnamediv>
74
 
 
 
57
  
75
58
  <refsynopsisdiv>
76
59
    <synopsis>&CONFPATH;</synopsis>
77
60
  </refsynopsisdiv>
78
 
 
 
61
  
79
62
  <refsect1 id="description">
80
63
    <title>DESCRIPTION</title>
81
64
    <para>
93
76
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
94
77
      to provide comments.
95
78
    </para>
96
 
 
 
79
    
97
80
  </refsect1>
98
81
  <refsect1>
99
82
    <title>OPTIONS</title>
106
89
          <xi:include href="mandos-options.xml" xpointer="interface"/>
107
90
        </listitem>
108
91
      </varlistentry>
109
 
 
 
92
      
110
93
      <varlistentry>
111
94
        <term><option>address<literal> = </literal><replaceable
112
95
          >ADDRESS</replaceable></option></term>
114
97
          <xi:include href="mandos-options.xml" xpointer="address"/>
115
98
        </listitem>
116
99
      </varlistentry>
117
 
 
 
100
      
118
101
      <varlistentry>
119
102
        <term><option>port<literal> = </literal><replaceable
120
103
        >NUMBER</replaceable></option></term>
122
105
          <xi:include href="mandos-options.xml" xpointer="port"/>
123
106
        </listitem>
124
107
      </varlistentry>
125
 
 
 
108
      
126
109
      <varlistentry>
127
110
        <term><option>debug<literal> = </literal>{ <literal
128
111
          >1</literal> | <literal>yes</literal> | <literal
133
116
          <xi:include href="mandos-options.xml" xpointer="debug"/>
134
117
        </listitem>
135
118
      </varlistentry>
136
 
 
 
119
      
137
120
      <varlistentry>
138
121
        <term><option>priority<literal> = </literal><replaceable
139
122
        >STRING</replaceable></option></term>
140
123
        <listitem>
141
 
          <xi:include href="mandos-options.xml" xpointer="priority"/>
 
124
          <xi:include href="mandos-options.xml"
 
125
                      xpointer="priority_compat"/>
142
126
        </listitem>
143
127
      </varlistentry>
144
 
 
 
128
      
145
129
      <varlistentry>
146
130
        <term><option>servicename<literal> = </literal
147
131
        ><replaceable>NAME</replaceable></option></term>
151
135
        </listitem>
152
136
      </varlistentry>
153
137
      
 
138
      <varlistentry>
 
139
        <term><option>use_dbus<literal> = </literal>{ <literal
 
140
          >1</literal> | <literal>yes</literal> | <literal
 
141
          >true</literal> | <literal>on</literal> | <literal
 
142
          >0</literal> | <literal>no</literal> | <literal
 
143
          >false</literal> | <literal>off</literal> }</option></term>
 
144
        <listitem>
 
145
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
 
146
        </listitem>
 
147
      </varlistentry>
 
148
      
 
149
      <varlistentry>
 
150
        <term><option>use_ipv6<literal> = </literal>{ <literal
 
151
          >1</literal> | <literal>yes</literal> | <literal
 
152
          >true</literal> | <literal>on</literal> | <literal
 
153
          >0</literal> | <literal>no</literal> | <literal
 
154
          >false</literal> | <literal>off</literal> }</option></term>
 
155
        <listitem>
 
156
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
 
157
        </listitem>
 
158
      </varlistentry>
 
159
      
 
160
      <varlistentry>
 
161
        <term><option>restore<literal> = </literal>{ <literal
 
162
          >1</literal> | <literal>yes</literal> | <literal
 
163
          >true</literal> | <literal>on</literal> | <literal
 
164
          >0</literal> | <literal>no</literal> | <literal
 
165
          >false</literal> | <literal>off</literal> }</option></term>
 
166
        <listitem>
 
167
          <xi:include href="mandos-options.xml" xpointer="restore"/>
 
168
        </listitem>
 
169
      </varlistentry>
 
170
      
 
171
      <varlistentry>
 
172
        <term><option>statedir<literal> = </literal><replaceable
 
173
        >DIRECTORY</replaceable></option></term>
 
174
        <listitem>
 
175
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
 
176
        </listitem>
 
177
      </varlistentry>
 
178
      
 
179
      <varlistentry>
 
180
        <term><option>socket<literal> = </literal><replaceable
 
181
        >NUMBER</replaceable></option></term>
 
182
        <listitem>
 
183
          <xi:include href="mandos-options.xml" xpointer="socket"/>
 
184
        </listitem>
 
185
      </varlistentry>
 
186
      
154
187
    </variablelist>
155
188
  </refsect1>
156
189
  
166
199
    <para>
167
200
      The <literal>[DEFAULT]</literal> is necessary because the Python
168
201
      built-in module <systemitem class="library">ConfigParser</systemitem>
169
 
      requres it.
 
202
      requires it.
170
203
    </para>
171
204
  </refsect1>
172
205
  
188
221
[DEFAULT]
189
222
# A configuration example
190
223
interface = eth0
191
 
address = 2001:db8:f983:bd0b:30de:ae4a:71f2:f672
 
224
address = fe80::aede:48ff:fe71:f6f2
192
225
port = 1025
193
226
debug = true
194
227
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
195
228
servicename = Daena
 
229
use_dbus = False
 
230
use_ipv6 = True
 
231
restore = True
 
232
statedir = /var/lib/mandos
196
233
      </programlisting>
197
234
    </informalexample>
198
235
  </refsect1>
200
237
  <refsect1 id="see_also">
201
238
    <title>SEE ALSO</title>
202
239
    <para>
 
240
      <citerefentry><refentrytitle>intro</refentrytitle>
 
241
      <manvolnum>8mandos</manvolnum></citerefentry>,
203
242
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
204
243
      ><manvolnum>3</manvolnum></citerefentry>,
205
244
      <citerefentry><refentrytitle>mandos</refentrytitle>
207
246
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
208
247
      <manvolnum>5</manvolnum></citerefentry>
209
248
    </para>
210
 
 
 
249
    
211
250
    <variablelist>
212
251
      <varlistentry>
213
252
        <term>
233
272
              <para>
234
273
                The clients use IPv6 link-local addresses, which are
235
274
                immediately usable since a link-local addresses is
236
 
                automatically assigned to a network interfaces when it
 
275
                automatically assigned to a network interface when it
237
276
                is brought up.
238
277
              </para>
239
278
            </listitem>