/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.xml

  • Committer: Teddy Hogeborn
  • Date: 2015-07-20 03:03:33 UTC
  • Revision ID: teddy@recompile.se-20150720030333-203m2aeblypcsfte
Bug fix for GnuTLS 3: be compatible with old 2048-bit DSA keys.

The mandos-keygen program in Mandos version 1.6.0 and older generated
2048-bit DSA keys, and when GnuTLS uses these it has trouble
connecting using the Mandos default priority string.  This was
previously fixed in Mandos 1.6.2, but the bug reappeared when using
GnuTLS 3, so the default priority string has to change again; this
time also the Mandos client has to change its default, so now the
server and the client should use the same default priority string:

SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA:+SIGN-DSA-SHA256

* mandos (main/server_defaults): Changed default priority string.
* mandos-options.xml (/section/para[id="priority_compat"]): Removed.
  (/section/para[id="priority"]): Changed default priority string.
* mandos.conf ([DEFAULT]/priority): - '' -
* mandos.conf.xml (OPTIONS/priority): Refer to the id "priority"
                                      instead of "priority_compat".
* mandos.xml (OPTIONS/--priority): - '' -
* plugins.d/mandos-client.c (main): Changed default priority string.

Show diffs side-by-side

added added

removed removed

Lines of Context:
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY COMMANDNAME "mandos">
5
 
<!ENTITY TIMESTAMP "2016-07-03">
 
5
<!ENTITY TIMESTAMP "2015-07-20">
6
6
<!ENTITY % common SYSTEM "common.ent">
7
7
%common;
8
8
]>
37
37
      <year>2011</year>
38
38
      <year>2012</year>
39
39
      <year>2013</year>
40
 
      <year>2014</year>
41
 
      <year>2015</year>
42
 
      <year>2016</year>
43
40
      <holder>Teddy Hogeborn</holder>
44
41
      <holder>Björn Påhlsson</holder>
45
42
    </copyright>
542
539
        </listitem>
543
540
      </varlistentry>
544
541
      <varlistentry>
 
542
        <term><filename class="devicefile">/dev/log</filename></term>
 
543
      </varlistentry>
 
544
      <varlistentry>
545
545
        <term><filename
546
546
        class="directory">/var/lib/mandos</filename></term>
547
547
        <listitem>
553
553
        </listitem>
554
554
      </varlistentry>
555
555
      <varlistentry>
556
 
        <term><filename class="devicefile">/dev/log</filename></term>
 
556
        <term><filename>/dev/log</filename></term>
557
557
        <listitem>
558
558
          <para>
559
559
            The Unix domain socket to where local syslog messages are
588
588
      This server does not check the expire time of clients’ OpenPGP
589
589
      keys.
590
590
    </para>
591
 
    <xi:include href="bugs.xml"/>
592
591
  </refsect1>
593
592
  
594
593
  <refsect1 id="example">
707
706
      </varlistentry>
708
707
      <varlistentry>
709
708
        <term>
710
 
          <ulink url="https://gnutls.org/">GnuTLS</ulink>
 
709
          <ulink url="http://gnutls.org/">GnuTLS</ulink>
711
710
        </term>
712
711
      <listitem>
713
712
        <para>