/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-07-20 03:03:33 UTC
  • Revision ID: teddy@recompile.se-20150720030333-203m2aeblypcsfte
Bug fix for GnuTLS 3: be compatible with old 2048-bit DSA keys.

The mandos-keygen program in Mandos version 1.6.0 and older generated
2048-bit DSA keys, and when GnuTLS uses these it has trouble
connecting using the Mandos default priority string.  This was
previously fixed in Mandos 1.6.2, but the bug reappeared when using
GnuTLS 3, so the default priority string has to change again; this
time also the Mandos client has to change its default, so now the
server and the client should use the same default priority string:

SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA:+SIGN-DSA-SHA256

* mandos (main/server_defaults): Changed default priority string.
* mandos-options.xml (/section/para[id="priority_compat"]): Removed.
  (/section/para[id="priority"]): Changed default priority string.
* mandos.conf ([DEFAULT]/priority): - '' -
* mandos.conf.xml (OPTIONS/priority): Refer to the id "priority"
                                      instead of "priority_compat".
* mandos.xml (OPTIONS/--priority): - '' -
* plugins.d/mandos-client.c (main): Changed default priority string.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version='1.0' encoding='UTF-8'?>
 
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY CONFNAME "mandos.conf">
6
5
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
7
 
<!ENTITY TIMESTAMP "2008-08-29">
 
6
<!ENTITY TIMESTAMP "2015-07-20">
 
7
<!ENTITY % common SYSTEM "common.ent">
 
8
%common;
8
9
]>
9
10
 
10
11
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
13
    <title>Mandos Manual</title>
13
14
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
15
    <productname>Mandos</productname>
15
 
    <productnumber>&VERSION;</productnumber>
 
16
    <productnumber>&version;</productnumber>
16
17
    <date>&TIMESTAMP;</date>
17
18
    <authorgroup>
18
19
      <author>
19
20
        <firstname>Björn</firstname>
20
21
        <surname>Påhlsson</surname>
21
22
        <address>
22
 
          <email>belorn@fukt.bsnet.se</email>
 
23
          <email>belorn@recompile.se</email>
23
24
        </address>
24
25
      </author>
25
26
      <author>
26
27
        <firstname>Teddy</firstname>
27
28
        <surname>Hogeborn</surname>
28
29
        <address>
29
 
          <email>teddy@fukt.bsnet.se</email>
 
30
          <email>teddy@recompile.se</email>
30
31
        </address>
31
32
      </author>
32
33
    </authorgroup>
33
34
    <copyright>
34
35
      <year>2008</year>
 
36
      <year>2009</year>
 
37
      <year>2011</year>
 
38
      <year>2012</year>
 
39
      <year>2013</year>
35
40
      <holder>Teddy Hogeborn</holder>
36
41
      <holder>Björn Påhlsson</holder>
37
42
    </copyright>
38
 
    <legalnotice>
39
 
      <para>
40
 
        This manual page is free software: you can redistribute it
41
 
        and/or modify it under the terms of the GNU General Public
42
 
        License as published by the Free Software Foundation,
43
 
        either version 3 of the License, or (at your option) any
44
 
        later version.
45
 
      </para>
46
 
 
47
 
      <para>
48
 
        This manual page is distributed in the hope that it will
49
 
        be useful, but WITHOUT ANY WARRANTY; without even the
50
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
51
 
        PARTICULAR PURPOSE.  See the GNU General Public License
52
 
        for more details.
53
 
      </para>
54
 
 
55
 
      <para>
56
 
        You should have received a copy of the GNU General Public
57
 
        License along with this program; If not, see
58
 
        <ulink url="http://www.gnu.org/licenses/"/>.
59
 
      </para>
60
 
    </legalnotice>
 
43
    <xi:include href="legalnotice.xml"/>
61
44
  </refentryinfo>
62
 
 
 
45
  
63
46
  <refmeta>
64
47
    <refentrytitle>&CONFNAME;</refentrytitle>
65
48
    <manvolnum>5</manvolnum>
71
54
      Configuration file for the Mandos server
72
55
    </refpurpose>
73
56
  </refnamediv>
74
 
 
 
57
  
75
58
  <refsynopsisdiv>
76
 
    <synopsis>
77
 
      &CONFPATH;
78
 
    </synopsis>
 
59
    <synopsis>&CONFPATH;</synopsis>
79
60
  </refsynopsisdiv>
80
 
 
 
61
  
81
62
  <refsect1 id="description">
82
63
    <title>DESCRIPTION</title>
83
64
    <para>
95
76
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
96
77
      to provide comments.
97
78
    </para>
98
 
 
 
79
    
99
80
  </refsect1>
100
81
  <refsect1>
101
82
    <title>OPTIONS</title>
102
83
    
103
84
    <variablelist>
104
85
      <varlistentry>
105
 
        <term><varname>interface</varname></term>
 
86
        <term><option>interface<literal> = </literal><replaceable
 
87
        >NAME</replaceable></option></term>
106
88
        <listitem>
107
 
          <synopsis><literal>interface = </literal><replaceable
108
 
          >NAME</replaceable>
109
 
          </synopsis>
110
89
          <xi:include href="mandos-options.xml" xpointer="interface"/>
111
90
        </listitem>
112
91
      </varlistentry>
113
 
 
 
92
      
114
93
      <varlistentry>
115
 
        <term><varname>address</varname></term>
 
94
        <term><option>address<literal> = </literal><replaceable
 
95
          >ADDRESS</replaceable></option></term>
116
96
        <listitem>
117
 
          <synopsis><literal>address = </literal><replaceable
118
 
          >ADDRESS</replaceable>
119
 
          </synopsis>
120
97
          <xi:include href="mandos-options.xml" xpointer="address"/>
121
98
        </listitem>
122
99
      </varlistentry>
123
 
 
 
100
      
124
101
      <varlistentry>
125
 
        <term><varname>port</varname></term>
 
102
        <term><option>port<literal> = </literal><replaceable
 
103
        >NUMBER</replaceable></option></term>
126
104
        <listitem>
127
 
          <synopsis><literal>port = </literal><replaceable
128
 
          >NUMBER</replaceable>
129
 
          </synopsis>
130
105
          <xi:include href="mandos-options.xml" xpointer="port"/>
131
106
        </listitem>
132
107
      </varlistentry>
133
 
 
 
108
      
134
109
      <varlistentry>
135
 
        <term><varname>debug</varname></term>
136
 
        <listitem>
137
 
          <synopsis><literal>debug = </literal>{ <literal
 
110
        <term><option>debug<literal> = </literal>{ <literal
138
111
          >1</literal> | <literal>yes</literal> | <literal
139
112
          >true</literal> | <literal>on</literal> | <literal
140
113
          >0</literal> | <literal>no</literal> | <literal
141
 
          >false</literal> | <literal>off</literal> }
142
 
          </synopsis>
 
114
          >false</literal> | <literal>off</literal> }</option></term>
 
115
        <listitem>
143
116
          <xi:include href="mandos-options.xml" xpointer="debug"/>
144
117
        </listitem>
145
118
      </varlistentry>
146
 
 
 
119
      
147
120
      <varlistentry>
148
 
        <term><varname>priority</varname></term>
 
121
        <term><option>priority<literal> = </literal><replaceable
 
122
        >STRING</replaceable></option></term>
149
123
        <listitem>
150
 
          <synopsis><literal>priority = </literal><replaceable
151
 
          >STRING</replaceable>
152
 
          </synopsis>
153
124
          <xi:include href="mandos-options.xml" xpointer="priority"/>
154
125
        </listitem>
155
126
      </varlistentry>
156
 
 
 
127
      
157
128
      <varlistentry>
158
 
        <term><varname>servicename</varname></term>
 
129
        <term><option>servicename<literal> = </literal
 
130
        ><replaceable>NAME</replaceable></option></term>
159
131
        <listitem>
160
 
          <synopsis><literal>servicename = </literal><replaceable
161
 
          >NAME</replaceable>
162
 
          </synopsis>
163
132
          <xi:include href="mandos-options.xml"
164
133
                      xpointer="servicename"/>
165
134
        </listitem>
166
135
      </varlistentry>
167
136
      
 
137
      <varlistentry>
 
138
        <term><option>use_dbus<literal> = </literal>{ <literal
 
139
          >1</literal> | <literal>yes</literal> | <literal
 
140
          >true</literal> | <literal>on</literal> | <literal
 
141
          >0</literal> | <literal>no</literal> | <literal
 
142
          >false</literal> | <literal>off</literal> }</option></term>
 
143
        <listitem>
 
144
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
 
145
        </listitem>
 
146
      </varlistentry>
 
147
      
 
148
      <varlistentry>
 
149
        <term><option>use_ipv6<literal> = </literal>{ <literal
 
150
          >1</literal> | <literal>yes</literal> | <literal
 
151
          >true</literal> | <literal>on</literal> | <literal
 
152
          >0</literal> | <literal>no</literal> | <literal
 
153
          >false</literal> | <literal>off</literal> }</option></term>
 
154
        <listitem>
 
155
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
 
156
        </listitem>
 
157
      </varlistentry>
 
158
      
 
159
      <varlistentry>
 
160
        <term><option>restore<literal> = </literal>{ <literal
 
161
          >1</literal> | <literal>yes</literal> | <literal
 
162
          >true</literal> | <literal>on</literal> | <literal
 
163
          >0</literal> | <literal>no</literal> | <literal
 
164
          >false</literal> | <literal>off</literal> }</option></term>
 
165
        <listitem>
 
166
          <xi:include href="mandos-options.xml" xpointer="restore"/>
 
167
        </listitem>
 
168
      </varlistentry>
 
169
      
 
170
      <varlistentry>
 
171
        <term><option>statedir<literal> = </literal><replaceable
 
172
        >DIRECTORY</replaceable></option></term>
 
173
        <listitem>
 
174
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
 
175
        </listitem>
 
176
      </varlistentry>
 
177
      
 
178
      <varlistentry>
 
179
        <term><option>socket<literal> = </literal><replaceable
 
180
        >NUMBER</replaceable></option></term>
 
181
        <listitem>
 
182
          <xi:include href="mandos-options.xml" xpointer="socket"/>
 
183
        </listitem>
 
184
      </varlistentry>
 
185
      
168
186
    </variablelist>
169
187
  </refsect1>
170
188
  
180
198
    <para>
181
199
      The <literal>[DEFAULT]</literal> is necessary because the Python
182
200
      built-in module <systemitem class="library">ConfigParser</systemitem>
183
 
      requres it.
 
201
      requires it.
184
202
    </para>
185
203
  </refsect1>
186
204
  
202
220
[DEFAULT]
203
221
# A configuration example
204
222
interface = eth0
205
 
address = 2001:db8:f983:bd0b:30de:ae4a:71f2:f672
 
223
address = fe80::aede:48ff:fe71:f6f2
206
224
port = 1025
207
 
debug = true
208
 
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
 
225
debug = True
 
226
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA
209
227
servicename = Daena
 
228
use_dbus = False
 
229
use_ipv6 = True
 
230
restore = True
 
231
statedir = /var/lib/mandos
210
232
      </programlisting>
211
233
    </informalexample>
212
234
  </refsect1>
214
236
  <refsect1 id="see_also">
215
237
    <title>SEE ALSO</title>
216
238
    <para>
 
239
      <citerefentry><refentrytitle>intro</refentrytitle>
 
240
      <manvolnum>8mandos</manvolnum></citerefentry>,
217
241
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
218
242
      ><manvolnum>3</manvolnum></citerefentry>,
219
243
      <citerefentry><refentrytitle>mandos</refentrytitle>
221
245
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
222
246
      <manvolnum>5</manvolnum></citerefentry>
223
247
    </para>
224
 
 
 
248
    
225
249
    <variablelist>
226
250
      <varlistentry>
227
251
        <term>
247
271
              <para>
248
272
                The clients use IPv6 link-local addresses, which are
249
273
                immediately usable since a link-local addresses is
250
 
                automatically assigned to a network interfaces when it
 
274
                automatically assigned to a network interface when it
251
275
                is brought up.
252
276
              </para>
253
277
            </listitem>