/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-07-20 03:03:33 UTC
  • Revision ID: teddy@recompile.se-20150720030333-203m2aeblypcsfte
Bug fix for GnuTLS 3: be compatible with old 2048-bit DSA keys.

The mandos-keygen program in Mandos version 1.6.0 and older generated
2048-bit DSA keys, and when GnuTLS uses these it has trouble
connecting using the Mandos default priority string.  This was
previously fixed in Mandos 1.6.2, but the bug reappeared when using
GnuTLS 3, so the default priority string has to change again; this
time also the Mandos client has to change its default, so now the
server and the client should use the same default priority string:

SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA:+SIGN-DSA-SHA256

* mandos (main/server_defaults): Changed default priority string.
* mandos-options.xml (/section/para[id="priority_compat"]): Removed.
  (/section/para[id="priority"]): Changed default priority string.
* mandos.conf ([DEFAULT]/priority): - '' -
* mandos.conf.xml (OPTIONS/priority): Refer to the id "priority"
                                      instead of "priority_compat".
* mandos.xml (OPTIONS/--priority): - '' -
* plugins.d/mandos-client.c (main): Changed default priority string.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version='1.0' encoding='UTF-8'?>
 
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY CONFNAME "mandos.conf">
6
5
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
7
 
<!ENTITY TIMESTAMP "2008-08-30">
 
6
<!ENTITY TIMESTAMP "2015-07-20">
 
7
<!ENTITY % common SYSTEM "common.ent">
 
8
%common;
8
9
]>
9
10
 
10
11
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
12
13
    <title>Mandos Manual</title>
13
14
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
15
    <productname>Mandos</productname>
15
 
    <productnumber>&VERSION;</productnumber>
 
16
    <productnumber>&version;</productnumber>
16
17
    <date>&TIMESTAMP;</date>
17
18
    <authorgroup>
18
19
      <author>
19
20
        <firstname>Björn</firstname>
20
21
        <surname>Påhlsson</surname>
21
22
        <address>
22
 
          <email>belorn@fukt.bsnet.se</email>
 
23
          <email>belorn@recompile.se</email>
23
24
        </address>
24
25
      </author>
25
26
      <author>
26
27
        <firstname>Teddy</firstname>
27
28
        <surname>Hogeborn</surname>
28
29
        <address>
29
 
          <email>teddy@fukt.bsnet.se</email>
 
30
          <email>teddy@recompile.se</email>
30
31
        </address>
31
32
      </author>
32
33
    </authorgroup>
33
34
    <copyright>
34
35
      <year>2008</year>
 
36
      <year>2009</year>
 
37
      <year>2011</year>
 
38
      <year>2012</year>
 
39
      <year>2013</year>
35
40
      <holder>Teddy Hogeborn</holder>
36
41
      <holder>Björn Påhlsson</holder>
37
42
    </copyright>
38
 
    <legalnotice>
39
 
      <para>
40
 
        This manual page is free software: you can redistribute it
41
 
        and/or modify it under the terms of the GNU General Public
42
 
        License as published by the Free Software Foundation,
43
 
        either version 3 of the License, or (at your option) any
44
 
        later version.
45
 
      </para>
46
 
 
47
 
      <para>
48
 
        This manual page is distributed in the hope that it will
49
 
        be useful, but WITHOUT ANY WARRANTY; without even the
50
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
51
 
        PARTICULAR PURPOSE.  See the GNU General Public License
52
 
        for more details.
53
 
      </para>
54
 
 
55
 
      <para>
56
 
        You should have received a copy of the GNU General Public
57
 
        License along with this program; If not, see
58
 
        <ulink url="http://www.gnu.org/licenses/"/>.
59
 
      </para>
60
 
    </legalnotice>
 
43
    <xi:include href="legalnotice.xml"/>
61
44
  </refentryinfo>
62
 
 
 
45
  
63
46
  <refmeta>
64
47
    <refentrytitle>&CONFNAME;</refentrytitle>
65
48
    <manvolnum>5</manvolnum>
71
54
      Configuration file for the Mandos server
72
55
    </refpurpose>
73
56
  </refnamediv>
74
 
 
 
57
  
75
58
  <refsynopsisdiv>
76
59
    <synopsis>&CONFPATH;</synopsis>
77
60
  </refsynopsisdiv>
78
 
 
 
61
  
79
62
  <refsect1 id="description">
80
63
    <title>DESCRIPTION</title>
81
64
    <para>
93
76
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
94
77
      to provide comments.
95
78
    </para>
96
 
 
 
79
    
97
80
  </refsect1>
98
81
  <refsect1>
99
82
    <title>OPTIONS</title>
106
89
          <xi:include href="mandos-options.xml" xpointer="interface"/>
107
90
        </listitem>
108
91
      </varlistentry>
109
 
 
 
92
      
110
93
      <varlistentry>
111
94
        <term><option>address<literal> = </literal><replaceable
112
95
          >ADDRESS</replaceable></option></term>
114
97
          <xi:include href="mandos-options.xml" xpointer="address"/>
115
98
        </listitem>
116
99
      </varlistentry>
117
 
 
 
100
      
118
101
      <varlistentry>
119
102
        <term><option>port<literal> = </literal><replaceable
120
103
        >NUMBER</replaceable></option></term>
122
105
          <xi:include href="mandos-options.xml" xpointer="port"/>
123
106
        </listitem>
124
107
      </varlistentry>
125
 
 
 
108
      
126
109
      <varlistentry>
127
110
        <term><option>debug<literal> = </literal>{ <literal
128
111
          >1</literal> | <literal>yes</literal> | <literal
133
116
          <xi:include href="mandos-options.xml" xpointer="debug"/>
134
117
        </listitem>
135
118
      </varlistentry>
136
 
 
 
119
      
137
120
      <varlistentry>
138
121
        <term><option>priority<literal> = </literal><replaceable
139
122
        >STRING</replaceable></option></term>
141
124
          <xi:include href="mandos-options.xml" xpointer="priority"/>
142
125
        </listitem>
143
126
      </varlistentry>
144
 
 
 
127
      
145
128
      <varlistentry>
146
129
        <term><option>servicename<literal> = </literal
147
130
        ><replaceable>NAME</replaceable></option></term>
151
134
        </listitem>
152
135
      </varlistentry>
153
136
      
 
137
      <varlistentry>
 
138
        <term><option>use_dbus<literal> = </literal>{ <literal
 
139
          >1</literal> | <literal>yes</literal> | <literal
 
140
          >true</literal> | <literal>on</literal> | <literal
 
141
          >0</literal> | <literal>no</literal> | <literal
 
142
          >false</literal> | <literal>off</literal> }</option></term>
 
143
        <listitem>
 
144
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
 
145
        </listitem>
 
146
      </varlistentry>
 
147
      
 
148
      <varlistentry>
 
149
        <term><option>use_ipv6<literal> = </literal>{ <literal
 
150
          >1</literal> | <literal>yes</literal> | <literal
 
151
          >true</literal> | <literal>on</literal> | <literal
 
152
          >0</literal> | <literal>no</literal> | <literal
 
153
          >false</literal> | <literal>off</literal> }</option></term>
 
154
        <listitem>
 
155
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
 
156
        </listitem>
 
157
      </varlistentry>
 
158
      
 
159
      <varlistentry>
 
160
        <term><option>restore<literal> = </literal>{ <literal
 
161
          >1</literal> | <literal>yes</literal> | <literal
 
162
          >true</literal> | <literal>on</literal> | <literal
 
163
          >0</literal> | <literal>no</literal> | <literal
 
164
          >false</literal> | <literal>off</literal> }</option></term>
 
165
        <listitem>
 
166
          <xi:include href="mandos-options.xml" xpointer="restore"/>
 
167
        </listitem>
 
168
      </varlistentry>
 
169
      
 
170
      <varlistentry>
 
171
        <term><option>statedir<literal> = </literal><replaceable
 
172
        >DIRECTORY</replaceable></option></term>
 
173
        <listitem>
 
174
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
 
175
        </listitem>
 
176
      </varlistentry>
 
177
      
 
178
      <varlistentry>
 
179
        <term><option>socket<literal> = </literal><replaceable
 
180
        >NUMBER</replaceable></option></term>
 
181
        <listitem>
 
182
          <xi:include href="mandos-options.xml" xpointer="socket"/>
 
183
        </listitem>
 
184
      </varlistentry>
 
185
      
154
186
    </variablelist>
155
187
  </refsect1>
156
188
  
166
198
    <para>
167
199
      The <literal>[DEFAULT]</literal> is necessary because the Python
168
200
      built-in module <systemitem class="library">ConfigParser</systemitem>
169
 
      requres it.
 
201
      requires it.
170
202
    </para>
171
203
  </refsect1>
172
204
  
188
220
[DEFAULT]
189
221
# A configuration example
190
222
interface = eth0
191
 
address = 2001:db8:f983:bd0b:30de:ae4a:71f2:f672
 
223
address = fe80::aede:48ff:fe71:f6f2
192
224
port = 1025
193
 
debug = true
194
 
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
 
225
debug = True
 
226
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA
195
227
servicename = Daena
 
228
use_dbus = False
 
229
use_ipv6 = True
 
230
restore = True
 
231
statedir = /var/lib/mandos
196
232
      </programlisting>
197
233
    </informalexample>
198
234
  </refsect1>
200
236
  <refsect1 id="see_also">
201
237
    <title>SEE ALSO</title>
202
238
    <para>
 
239
      <citerefentry><refentrytitle>intro</refentrytitle>
 
240
      <manvolnum>8mandos</manvolnum></citerefentry>,
203
241
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
204
242
      ><manvolnum>3</manvolnum></citerefentry>,
205
243
      <citerefentry><refentrytitle>mandos</refentrytitle>
207
245
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
208
246
      <manvolnum>5</manvolnum></citerefentry>
209
247
    </para>
210
 
 
 
248
    
211
249
    <variablelist>
212
250
      <varlistentry>
213
251
        <term>
233
271
              <para>
234
272
                The clients use IPv6 link-local addresses, which are
235
273
                immediately usable since a link-local addresses is
236
 
                automatically assigned to a network interfaces when it
 
274
                automatically assigned to a network interface when it
237
275
                is brought up.
238
276
              </para>
239
277
            </listitem>