/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos-ctl.xml

  • Committer: Teddy Hogeborn
  • Date: 2016-03-04 22:07:35 UTC
  • Revision ID: teddy@recompile.se-20160304220735-4xeeqt5p4nhw5cuh
Restrict the Mandos server daemon in the systemd service file.

* mandos.service ([Service]/ProtectSystem): Set to "full".
 ([Service]/PrivateTmp, [Service]/PrivateDevices,
  [Service]/ProtectHome): Set to "yes".
 ([Service]/CapabilityBoundingSet): Set to "CAP_SETUID
                                    CAP_DAC_OVERRIDE CAP_NET_RAW".

Show diffs side-by-side

added added

removed removed

Lines of Context:
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
4
<!ENTITY COMMANDNAME "mandos-ctl">
5
 
<!ENTITY TIMESTAMP "2016-06-27">
 
5
<!ENTITY TIMESTAMP "2016-02-28">
6
6
<!ENTITY % common SYSTEM "common.ent">
7
7
%common;
8
8
]>
52
52
  <refnamediv>
53
53
    <refname><command>&COMMANDNAME;</command></refname>
54
54
    <refpurpose>
55
 
      Control or query the operation of the Mandos server
 
55
      Control the operation of the Mandos server
56
56
    </refpurpose>
57
57
  </refnamediv>
58
58
  
59
59
  <refsynopsisdiv>
60
60
    <cmdsynopsis>
61
61
      <command>&COMMANDNAME;</command>
62
 
      <group choice="req">
63
 
        <group>
64
 
          <arg choice="plain"><option>--enable</option></arg>
65
 
          <arg choice="plain"><option>-e</option></arg>
66
 
          <sbr/>
67
 
          <arg choice="plain"><option>--disable</option></arg>
68
 
          <arg choice="plain"><option>-d</option></arg>
69
 
        </group>
70
 
        <sbr/>
71
 
        <group>
72
 
          <arg choice="plain"><option>--bump-timeout</option></arg>
73
 
          <arg choice="plain"><option>-b</option></arg>
74
 
        </group>
75
 
        <sbr/>
76
 
        <group>
77
 
          <arg choice="plain"><option>--start-checker</option></arg>
78
 
        </group>
79
 
        <sbr/>
80
 
        <group>
81
 
          <arg choice="plain"><option>--stop-checker</option></arg>
82
 
        </group>
83
 
        <sbr/>
84
 
        <group>
85
 
          <arg choice="plain"><option>--remove</option></arg>
86
 
          <arg choice="plain"><option>-r</option></arg>
87
 
        </group>
88
 
        <sbr/>
89
 
        <group>
90
 
          <arg choice="plain"><option>--checker
91
 
          <replaceable>COMMAND</replaceable></option></arg>
92
 
          <arg choice="plain"><option>-c
93
 
          <replaceable>COMMAND</replaceable></option></arg>
94
 
        </group>
95
 
        <sbr/>
96
 
        <group>
97
 
          <arg choice="plain"><option>--timeout
98
 
          <replaceable>TIME</replaceable></option></arg>
99
 
          <arg choice="plain"><option>-t
100
 
          <replaceable>TIME</replaceable></option></arg>
101
 
        </group>
102
 
        <sbr/>
103
 
        <group>
104
 
          <arg choice="plain"><option>--extended-timeout
105
 
          <replaceable>TIME</replaceable></option></arg>
106
 
        </group>
107
 
        <sbr/>
108
 
        <group>
109
 
          <arg choice="plain"><option>--interval
110
 
          <replaceable>TIME</replaceable></option></arg>
111
 
          <arg choice="plain"><option>-i
112
 
          <replaceable>TIME</replaceable></option></arg>
113
 
        </group>
114
 
        <sbr/>
115
 
        <group>
116
 
          <arg choice="plain"><option>--approve-by-default</option
117
 
          ></arg>
118
 
          <sbr/>
119
 
          <arg choice="plain"><option>--deny-by-default</option></arg>
120
 
        </group>
121
 
        <sbr/>
122
 
        <group>
123
 
          <arg choice="plain"><option>--approval-delay
124
 
          <replaceable>TIME</replaceable></option></arg>
125
 
        </group>
126
 
        <sbr/>
127
 
        <group>
128
 
          <arg choice="plain"><option>--approval-duration
129
 
          <replaceable>TIME</replaceable></option></arg>
130
 
        </group>
131
 
        <sbr/>
132
 
        <group>
133
 
          <arg choice="plain"><option>--interval
134
 
          <replaceable>TIME</replaceable></option></arg>
135
 
          <arg choice="plain"><option>-i
136
 
          <replaceable>TIME</replaceable></option></arg>
137
 
        </group>
138
 
        <sbr/>
139
 
        <group>
140
 
          <arg choice="plain"><option>--host
141
 
          <replaceable>STRING</replaceable></option></arg>
142
 
          <arg choice="plain"><option>-H
143
 
          <replaceable>STRING</replaceable></option></arg>
144
 
        </group>
145
 
        <sbr/>
146
 
        <group>
147
 
          <arg choice="plain"><option>--secret
148
 
          <replaceable>FILENAME</replaceable></option></arg>
149
 
          <arg choice="plain"><option>-s
150
 
          <replaceable>FILENAME</replaceable></option></arg>
151
 
        </group>
152
 
        <sbr/>
153
 
        <group>
154
 
          <arg choice="plain"><option>--approve</option></arg>
155
 
          <arg choice="plain"><option>-A</option></arg>
156
 
          <sbr/>
157
 
          <arg choice="plain"><option>--deny</option></arg>
158
 
          <arg choice="plain"><option>-D</option></arg>
159
 
        </group>
 
62
      <group>
 
63
        <arg choice="plain"><option>--enable</option></arg>
 
64
        <arg choice="plain"><option>-e</option></arg>
 
65
        <sbr/>
 
66
        <arg choice="plain"><option>--disable</option></arg>
 
67
        <arg choice="plain"><option>-d</option></arg>
 
68
      </group>
 
69
      <sbr/>
 
70
      <group>
 
71
        <arg choice="plain"><option>--bump-timeout</option></arg>
 
72
        <arg choice="plain"><option>-b</option></arg>
 
73
      </group>
 
74
      <sbr/>
 
75
      <group>
 
76
        <arg choice="plain"><option>--start-checker</option></arg>
 
77
      </group>
 
78
      <sbr/>
 
79
      <group>
 
80
        <arg choice="plain"><option>--stop-checker</option></arg>
 
81
      </group>
 
82
      <sbr/>
 
83
      <group>
 
84
        <arg choice="plain"><option>--remove</option></arg>
 
85
        <arg choice="plain"><option>-r</option></arg>
 
86
      </group>
 
87
      <sbr/>
 
88
      <group>
 
89
        <arg choice="plain"><option>--checker
 
90
        <replaceable>COMMAND</replaceable></option></arg>
 
91
        <arg choice="plain"><option>-c
 
92
        <replaceable>COMMAND</replaceable></option></arg>
 
93
      </group>
 
94
      <sbr/>
 
95
      <group>
 
96
        <arg choice="plain"><option>--timeout
 
97
        <replaceable>TIME</replaceable></option></arg>
 
98
        <arg choice="plain"><option>-t
 
99
        <replaceable>TIME</replaceable></option></arg>
 
100
      </group>
 
101
      <sbr/>
 
102
      <group>
 
103
        <arg choice="plain"><option>--extended-timeout
 
104
        <replaceable>TIME</replaceable></option></arg>
 
105
      </group>
 
106
      <sbr/>
 
107
      <group>
 
108
        <arg choice="plain"><option>--interval
 
109
        <replaceable>TIME</replaceable></option></arg>
 
110
        <arg choice="plain"><option>-i
 
111
        <replaceable>TIME</replaceable></option></arg>
 
112
      </group>
 
113
      <sbr/>
 
114
      <group>
 
115
        <arg choice="plain"><option>--approve-by-default</option
 
116
        ></arg>
 
117
        <sbr/>
 
118
        <arg choice="plain"><option>--deny-by-default</option></arg>
 
119
      </group>
 
120
      <sbr/>
 
121
      <group>
 
122
        <arg choice="plain"><option>--approval-delay
 
123
        <replaceable>TIME</replaceable></option></arg>
 
124
      </group>
 
125
      <sbr/>
 
126
      <group>
 
127
        <arg choice="plain"><option>--approval-duration
 
128
        <replaceable>TIME</replaceable></option></arg>
 
129
      </group>
 
130
      <sbr/>
 
131
      <group>
 
132
        <arg choice="plain"><option>--interval
 
133
        <replaceable>TIME</replaceable></option></arg>
 
134
        <arg choice="plain"><option>-i
 
135
        <replaceable>TIME</replaceable></option></arg>
 
136
      </group>
 
137
      <sbr/>
 
138
      <group>
 
139
        <arg choice="plain"><option>--host
 
140
        <replaceable>STRING</replaceable></option></arg>
 
141
        <arg choice="plain"><option>-H
 
142
        <replaceable>STRING</replaceable></option></arg>
 
143
      </group>
 
144
      <sbr/>
 
145
      <group>
 
146
        <arg choice="plain"><option>--secret
 
147
        <replaceable>FILENAME</replaceable></option></arg>
 
148
        <arg choice="plain"><option>-s
 
149
        <replaceable>FILENAME</replaceable></option></arg>
 
150
      </group>
 
151
      <sbr/>
 
152
      <group>
 
153
        <arg choice="plain"><option>--approve</option></arg>
 
154
        <arg choice="plain"><option>-A</option></arg>
 
155
        <sbr/>
 
156
        <arg choice="plain"><option>--deny</option></arg>
 
157
        <arg choice="plain"><option>-D</option></arg>
160
158
      </group>
161
159
      <sbr/>
162
160
      <group choice="req">
170
168
    <cmdsynopsis>
171
169
      <command>&COMMANDNAME;</command>
172
170
      <group>
173
 
          <arg choice="plain"><option>--verbose</option></arg>
174
 
          <arg choice="plain"><option>-v</option></arg>
175
 
          <sbr/>
176
 
          <arg choice="plain"><option>--dump-json</option></arg>
177
 
          <arg choice="plain"><option>-j</option></arg>
 
171
        <arg choice="plain"><option>--verbose</option></arg>
 
172
        <arg choice="plain"><option>-v</option></arg>
178
173
      </group>
179
174
      <group>
180
175
        <arg rep='repeat' choice='plain'>
213
208
  <refsect1 id="description">
214
209
    <title>DESCRIPTION</title>
215
210
    <para>
216
 
      <command>&COMMANDNAME;</command> is a program to control or
217
 
      query the operation of the Mandos server
218
 
      <citerefentry><refentrytitle>mandos</refentrytitle><manvolnum
219
 
      >8</manvolnum></citerefentry>.
 
211
      <command>&COMMANDNAME;</command> is a program to control the
 
212
      operation of the Mandos server <citerefentry><refentrytitle
 
213
      >mandos</refentrytitle><manvolnum>8</manvolnum></citerefentry>.
220
214
    </para>
221
215
    <para>
222
216
      This program can be used to change client settings, approve or
480
474
      </varlistentry>
481
475
      
482
476
      <varlistentry>
483
 
        <term><option>--dump-json</option></term>
484
 
        <term><option>-j</option></term>
485
 
        <listitem>
486
 
          <para>
487
 
            Dump client settings as JSON to standard output.
488
 
          </para>
489
 
        </listitem>
490
 
      </varlistentry>
491
 
      
492
 
      <varlistentry>
493
477
        <term><option>--is-enabled</option></term>
494
478
        <term><option>-V</option></term>
495
479
        <listitem>
530
514
    </para>
531
515
  </refsect1>
532
516
  
533
 
  <refsect1 id="bugs">
534
 
    <title>BUGS</title>
535
 
    <xi:include href="bugs.xml"/>
536
 
  </refsect1>
 
517
<!--   <refsect1 id="bugs"> -->
 
518
<!--     <title>BUGS</title> -->
 
519
<!--     <para> -->
 
520
<!--     </para> -->
 
521
<!--   </refsect1> -->
537
522
  
538
523
  <refsect1 id="example">
539
524
    <title>EXAMPLE</title>