/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to intro.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-05-22 20:23:46 UTC
  • Revision ID: teddy@recompile.se-20150522202346-taccq232srbszyd9
mandos-keygen: Bug fix: Only use one SSH key from ssh-keyscan

If ssh-keyscan found keys of more than one type, the generated output
would be incorrect.  Restrict the output to one type of key.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY TIMESTAMP "2014-06-22">
 
4
<!ENTITY TIMESTAMP "2015-03-08">
5
5
<!ENTITY % common SYSTEM "common.ent">
6
6
%common;
7
7
]>
197
197
      </para>
198
198
    </refsect2>
199
199
    
 
200
    <refsect2 id="sniff">
 
201
      <title>How about sniffing the network traffic and decrypting it
 
202
      later by physically grabbing the Mandos client and using its
 
203
      key?</title>
 
204
      <para>
 
205
        We only use <acronym>PFS</acronym> (Perfect Forward Security)
 
206
        key exchange algorithms in TLS, which protects against this.
 
207
      </para>
 
208
    </refsect2>
 
209
    
200
210
    <refsect2 id="physgrab">
201
211
      <title>Physically grabbing the Mandos server computer?</title>
202
212
      <para>