/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to network-hooks.d/wireless.conf

  • Committer: Teddy Hogeborn
  • Date: 2015-03-10 18:52:09 UTC
  • Revision ID: teddy@recompile.se-20150310185209-lxuovbu09zwyk9bx
Automatically determine the number of DH bits in the TLS handshake.

Instead of using a default value of 1024, check the OpenPGP key and
determine an appropriate number of DH bits to use, (using GnuTLS
functions made for this).  Document this new default behavior.

* plugins.d/mandos-client.c (safe_string): New function.
  (init_gnutls_global): If not specified, determine the number of DH
                        bits to use, based on the OpenPGP key.
* plugins.d/mandos-client.xml (OPTIONS): Document this new default of
                                         the --dh-bits option.

Thanks to Andreas Fischer <af@bantuX.org> for reporting this issue.

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
# Extra options for wpa_supplicant, if any
 
2
#WPAS_OPTIONS=""
 
3
 
 
4
# wlan0
 
5
ADDRESS_0=00:11:22:33:44:55
 
6
MODULE_0=ath9k
 
7
#WPA_DRIVER_0=wext
 
8
wpa_interface_0(){
 
9
    # Use this format to set simple things:
 
10
    wpa_cli_set ssid home
 
11
    wpa_cli_set psk "secret passphrase"
 
12
    # Use this format to do more complex things with wpa_cli:
 
13
    #"$wpa_cli" -p "$CTRLDIR" -i "$INTERFACE" bssid "$NETWORK" 00:11:22:33:44:55
 
14
    #"$wpa_cli" -g "$CTRL" ping
 
15
}
 
16
#DELAY_0=10
 
17
IPADDRS_0=dhcp
 
18
#IPADDRS_0="192.0.2.3/24 2001:DB8::aede:48ff:fe71:f6f2/32"
 
19
#ROUTES_0="192.0.2.0/24 2001:DB8::/32"
 
20
 
 
21
#ADDRESS_1=11:22:33:44:55:66
 
22
#MODULE_1=...
 
23
#...