/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to mandos.conf.xml

  • Committer: Teddy Hogeborn
  • Date: 2016-06-03 17:27:03 UTC
  • Revision ID: teddy@recompile.se-20160603172703-mc6tjor6rhq4xy74
mandos: Bug fix: Do multiprocessing cleanup correctly on exit

* mandos (main): Save module "multiprocessing" and open file "wnull"
                 as scope variables accessible by function cleanup(),
                 since the module and global variable may not be
                 accessible when the cleanup() function is run as
                 scheduled by atexit().

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
<?xml version='1.0' encoding='UTF-8'?>
 
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY CONFNAME "mandos.conf">
6
5
<!ENTITY CONFPATH "<filename>/etc/mandos/mandos.conf</filename>">
7
 
<!ENTITY OVERVIEW SYSTEM "overview.xml">
 
6
<!ENTITY TIMESTAMP "2016-03-05">
 
7
<!ENTITY % common SYSTEM "common.ent">
 
8
%common;
8
9
]>
9
10
 
10
 
<refentry>
 
11
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
11
12
  <refentryinfo>
12
 
    <title>&CONFNAME;</title>
 
13
    <title>Mandos Manual</title>
13
14
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
14
 
    <productname>&CONFNAME;</productname>
15
 
    <productnumber>&VERSION;</productnumber>
 
15
    <productname>Mandos</productname>
 
16
    <productnumber>&version;</productnumber>
 
17
    <date>&TIMESTAMP;</date>
16
18
    <authorgroup>
17
19
      <author>
18
20
        <firstname>Björn</firstname>
19
21
        <surname>Påhlsson</surname>
20
22
        <address>
21
 
          <email>belorn@fukt.bsnet.se</email>
 
23
          <email>belorn@recompile.se</email>
22
24
        </address>
23
25
      </author>
24
26
      <author>
25
27
        <firstname>Teddy</firstname>
26
28
        <surname>Hogeborn</surname>
27
29
        <address>
28
 
          <email>teddy@fukt.bsnet.se</email>
 
30
          <email>teddy@recompile.se</email>
29
31
        </address>
30
32
      </author>
31
33
    </authorgroup>
32
34
    <copyright>
33
35
      <year>2008</year>
 
36
      <year>2009</year>
 
37
      <year>2010</year>
 
38
      <year>2011</year>
 
39
      <year>2012</year>
 
40
      <year>2013</year>
 
41
      <year>2014</year>
 
42
      <year>2015</year>
 
43
      <year>2016</year>
34
44
      <holder>Teddy Hogeborn</holder>
35
45
      <holder>Björn Påhlsson</holder>
36
46
    </copyright>
37
 
    <legalnotice>
38
 
      <para>
39
 
        This manual page is free software: you can redistribute it
40
 
        and/or modify it under the terms of the GNU General Public
41
 
        License as published by the Free Software Foundation,
42
 
        either version 3 of the License, or (at your option) any
43
 
        later version.
44
 
      </para>
45
 
 
46
 
      <para>
47
 
        This manual page is distributed in the hope that it will
48
 
        be useful, but WITHOUT ANY WARRANTY; without even the
49
 
        implied warranty of MERCHANTABILITY or FITNESS FOR A
50
 
        PARTICULAR PURPOSE.  See the GNU General Public License
51
 
        for more details.
52
 
      </para>
53
 
 
54
 
      <para>
55
 
        You should have received a copy of the GNU General Public
56
 
        License along with this program; If not, see
57
 
        <ulink url="http://www.gnu.org/licenses/"/>.
58
 
      </para>
59
 
    </legalnotice>
 
47
    <xi:include href="legalnotice.xml"/>
60
48
  </refentryinfo>
61
 
 
 
49
  
62
50
  <refmeta>
63
51
    <refentrytitle>&CONFNAME;</refentrytitle>
64
52
    <manvolnum>5</manvolnum>
70
58
      Configuration file for the Mandos server
71
59
    </refpurpose>
72
60
  </refnamediv>
73
 
 
 
61
  
74
62
  <refsynopsisdiv>
75
 
    <synopsis>
76
 
      &CONFPATH;
77
 
    </synopsis>
 
63
    <synopsis>&CONFPATH;</synopsis>
78
64
  </refsynopsisdiv>
79
 
 
 
65
  
80
66
  <refsect1 id="description">
81
67
    <title>DESCRIPTION</title>
82
68
    <para>
83
69
      The file &CONFPATH; is a simple configuration file for
84
70
      <citerefentry><refentrytitle>mandos</refentrytitle>
85
71
      <manvolnum>8</manvolnum></citerefentry>, and is read by it at
86
 
      startup.  The configuration file starts with
87
 
      <quote><literal>[DEFAULT]</literal></quote> on a line by itself,
88
 
      followed by any number of
89
 
      <quote><varname><replaceable>option</replaceable></varname>=<replaceable>value</replaceable></quote>
90
 
      entries, with continuations in the style of RFC 822.
91
 
      <quote><varname><replaceable>option</replaceable></varname>:
92
 
      <replaceable>value</replaceable></quote> is also accepted.  Note
93
 
      that leading whitespace is removed from values.  Lines beginning
94
 
      with <quote>#</quote> or <quote>;</quote> are ignored and may be
95
 
      used to provide comments.
96
 
    </para>
97
 
 
98
 
    <para>
99
 
      The options are:
100
 
    </para>
101
 
 
 
72
      startup.  The configuration file starts with <quote><literal
 
73
      >[DEFAULT]</literal></quote> on a line by itself, followed by
 
74
      any number of <quote><varname><replaceable>option</replaceable
 
75
      ></varname>=<replaceable>value</replaceable></quote> entries,
 
76
      with continuations in the style of RFC 822.  <quote><varname
 
77
      ><replaceable>option</replaceable></varname>: <replaceable
 
78
      >value</replaceable></quote> is also accepted.  Note that
 
79
      leading whitespace is removed from values.  Lines beginning with
 
80
      <quote>#</quote> or <quote>;</quote> are ignored and may be used
 
81
      to provide comments.
 
82
    </para>
 
83
    
 
84
  </refsect1>
 
85
  <refsect1>
 
86
    <title>OPTIONS</title>
 
87
    
102
88
    <variablelist>
103
89
      <varlistentry>
104
 
        <term><literal><varname>interface</varname></literal></term>
105
 
        <listitem>
106
 
          <para>
107
 
            This option allows you to override the default network
108
 
            interfaces. By default mandos will not bind to any
109
 
            specific interface but instead use default avahi-server
110
 
            behaviour.
111
 
          </para>
112
 
        </listitem>
113
 
      </varlistentry>
114
 
 
115
 
      <varlistentry>
116
 
        <term><literal><varname>address</varname></literal></term>
117
 
        <listitem>
118
 
          <para>
119
 
            This option allows you to override the default network
120
 
            address. By default mandos will not bind to any
121
 
            specific address but instead use default avahi-server
122
 
            behaviour.
123
 
          </para>
124
 
        </listitem>
125
 
      </varlistentry>      
126
 
 
127
 
      <varlistentry>
128
 
        <term><literal><varname>port</varname></literal></term>
129
 
        <listitem>
130
 
          <para>
131
 
            This option allows you to override the default port to
132
 
            listen on. By default mandos will not specify any specific
133
 
            port and instead use a random port given by the OS from
134
 
            the use of INADDR_ANY.
135
 
          </para>
136
 
        </listitem>
137
 
      </varlistentry>
138
 
 
139
 
      <varlistentry>
140
 
        <term><literal><varname>debug</varname></literal></term>
141
 
        <listitem>
142
 
          <para>
143
 
            This option allows you to modify debug mode with a true/false
144
 
            boolean value. By default is debug set to <literal>false</literal>.
145
 
          </para>
146
 
        </listitem>
147
 
      </varlistentry>      
148
 
 
149
 
      <varlistentry>
150
 
        <term><literal><varname>priority</varname></literal></term>
151
 
        <listitem>
152
 
          <para>
153
 
            This option allows you to override the default gnutls
154
 
            priority that will be used in gnutls session. See
155
 
            <citerefentry><refentrytitle>gnutls_priority_init
156
 
            </refentrytitle><manvolnum>3</manvolnum></citerefentry>for
157
 
            more information on gnutls priority strings.
158
 
          </para>         
159
 
        </listitem>
160
 
      </varlistentry>
161
 
 
162
 
      <varlistentry>
163
 
        <term><literal><varname>servicename</varname></literal></term>
164
 
        <listitem>
165
 
          <para>
166
 
            This option allows you to override the default Zeroconf
167
 
            service name use to announce mandos as a avahi service. By
168
 
            default mandos will use "Mandos".
169
 
          </para>
 
90
        <term><option>interface<literal> = </literal><replaceable
 
91
        >NAME</replaceable></option></term>
 
92
        <listitem>
 
93
          <xi:include href="mandos-options.xml" xpointer="interface"/>
 
94
        </listitem>
 
95
      </varlistentry>
 
96
      
 
97
      <varlistentry>
 
98
        <term><option>address<literal> = </literal><replaceable
 
99
          >ADDRESS</replaceable></option></term>
 
100
        <listitem>
 
101
          <xi:include href="mandos-options.xml" xpointer="address"/>
 
102
        </listitem>
 
103
      </varlistentry>
 
104
      
 
105
      <varlistentry>
 
106
        <term><option>port<literal> = </literal><replaceable
 
107
        >NUMBER</replaceable></option></term>
 
108
        <listitem>
 
109
          <xi:include href="mandos-options.xml" xpointer="port"/>
 
110
        </listitem>
 
111
      </varlistentry>
 
112
      
 
113
      <varlistentry>
 
114
        <term><option>debug<literal> = </literal>{ <literal
 
115
          >1</literal> | <literal>yes</literal> | <literal
 
116
          >true</literal> | <literal>on</literal> | <literal
 
117
          >0</literal> | <literal>no</literal> | <literal
 
118
          >false</literal> | <literal>off</literal> }</option></term>
 
119
        <listitem>
 
120
          <xi:include href="mandos-options.xml" xpointer="debug"/>
 
121
        </listitem>
 
122
      </varlistentry>
 
123
      
 
124
      <varlistentry>
 
125
        <term><option>priority<literal> = </literal><replaceable
 
126
        >STRING</replaceable></option></term>
 
127
        <listitem>
 
128
          <xi:include href="mandos-options.xml" xpointer="priority"/>
 
129
        </listitem>
 
130
      </varlistentry>
 
131
      
 
132
      <varlistentry>
 
133
        <term><option>servicename<literal> = </literal
 
134
        ><replaceable>NAME</replaceable></option></term>
 
135
        <listitem>
 
136
          <xi:include href="mandos-options.xml"
 
137
                      xpointer="servicename"/>
 
138
        </listitem>
 
139
      </varlistentry>
 
140
      
 
141
      <varlistentry>
 
142
        <term><option>use_dbus<literal> = </literal>{ <literal
 
143
          >1</literal> | <literal>yes</literal> | <literal
 
144
          >true</literal> | <literal>on</literal> | <literal
 
145
          >0</literal> | <literal>no</literal> | <literal
 
146
          >false</literal> | <literal>off</literal> }</option></term>
 
147
        <listitem>
 
148
          <xi:include href="mandos-options.xml" xpointer="dbus"/>
 
149
        </listitem>
 
150
      </varlistentry>
 
151
      
 
152
      <varlistentry>
 
153
        <term><option>use_ipv6<literal> = </literal>{ <literal
 
154
          >1</literal> | <literal>yes</literal> | <literal
 
155
          >true</literal> | <literal>on</literal> | <literal
 
156
          >0</literal> | <literal>no</literal> | <literal
 
157
          >false</literal> | <literal>off</literal> }</option></term>
 
158
        <listitem>
 
159
          <xi:include href="mandos-options.xml" xpointer="ipv6"/>
 
160
        </listitem>
 
161
      </varlistentry>
 
162
      
 
163
      <varlistentry>
 
164
        <term><option>restore<literal> = </literal>{ <literal
 
165
          >1</literal> | <literal>yes</literal> | <literal
 
166
          >true</literal> | <literal>on</literal> | <literal
 
167
          >0</literal> | <literal>no</literal> | <literal
 
168
          >false</literal> | <literal>off</literal> }</option></term>
 
169
        <listitem>
 
170
          <xi:include href="mandos-options.xml" xpointer="restore"/>
 
171
        </listitem>
 
172
      </varlistentry>
 
173
      
 
174
      <varlistentry>
 
175
        <term><option>statedir<literal> = </literal><replaceable
 
176
        >DIRECTORY</replaceable></option></term>
 
177
        <listitem>
 
178
          <xi:include href="mandos-options.xml" xpointer="statedir"/>
 
179
        </listitem>
 
180
      </varlistentry>
 
181
      
 
182
      <varlistentry>
 
183
        <term><option>socket<literal> = </literal><replaceable
 
184
        >NUMBER</replaceable></option></term>
 
185
        <listitem>
 
186
          <xi:include href="mandos-options.xml" xpointer="socket"/>
170
187
        </listitem>
171
188
      </varlistentry>
172
189
      
173
190
    </variablelist>
174
191
  </refsect1>
175
 
 
176
 
  <refsect1 id="examples">
177
 
    <title>EXAMPLES</title>
178
 
    <informalexample>
179
 
      <programlisting>
180
 
        [server]
181
 
        # A configuration example
182
 
        interface = eth0 
183
 
        address = 2001:DB8:
184
 
        port = 1025 
185
 
        debug = true 
186
 
        priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP
187
 
        servicename = Mandos
188
 
      </programlisting>
189
 
    </informalexample>
190
 
  </refsect1>  
191
192
  
192
193
  <refsect1 id="files">
193
194
    <title>FILES</title>
195
196
      The file described here is &CONFPATH;
196
197
    </para>
197
198
  </refsect1>
 
199
  
 
200
  <refsect1 id="bugs">
 
201
    <title>BUGS</title>
 
202
    <para>
 
203
      The <literal>[DEFAULT]</literal> is necessary because the Python
 
204
      built-in module <systemitem class="library">ConfigParser</systemitem>
 
205
      requires it.
 
206
    </para>
 
207
    <xi:include href="bugs.xml"/>
 
208
  </refsect1>
 
209
  
 
210
  <refsect1 id="example">
 
211
    <title>EXAMPLE</title>
 
212
    <informalexample>
 
213
      <para>
 
214
        No options are actually required:
 
215
      </para>
 
216
      <programlisting>
 
217
[DEFAULT]
 
218
      </programlisting>
 
219
    </informalexample>
 
220
    <informalexample>
 
221
      <para>
 
222
        An example using all the options:
 
223
      </para>
 
224
      <programlisting>
 
225
[DEFAULT]
 
226
# A configuration example
 
227
interface = eth0
 
228
address = fe80::aede:48ff:fe71:f6f2
 
229
port = 1025
 
230
debug = True
 
231
priority = SECURE256:!CTYPE-X.509:+CTYPE-OPENPGP:!RSA
 
232
servicename = Daena
 
233
use_dbus = False
 
234
use_ipv6 = True
 
235
restore = True
 
236
statedir = /var/lib/mandos
 
237
      </programlisting>
 
238
    </informalexample>
 
239
  </refsect1>
 
240
  
 
241
  <refsect1 id="see_also">
 
242
    <title>SEE ALSO</title>
 
243
    <para>
 
244
      <citerefentry><refentrytitle>intro</refentrytitle>
 
245
      <manvolnum>8mandos</manvolnum></citerefentry>,
 
246
      <citerefentry><refentrytitle>gnutls_priority_init</refentrytitle
 
247
      ><manvolnum>3</manvolnum></citerefentry>,
 
248
      <citerefentry><refentrytitle>mandos</refentrytitle>
 
249
      <manvolnum>8</manvolnum></citerefentry>,
 
250
      <citerefentry><refentrytitle>mandos-clients.conf</refentrytitle>
 
251
      <manvolnum>5</manvolnum></citerefentry>
 
252
    </para>
 
253
    
 
254
    <variablelist>
 
255
      <varlistentry>
 
256
        <term>
 
257
          RFC 4291: <citetitle>IP Version 6 Addressing
 
258
          Architecture</citetitle>
 
259
        </term>
 
260
        <listitem>
 
261
          <variablelist>
 
262
            <varlistentry>
 
263
              <term>Section 2.2: <citetitle>Text Representation of
 
264
              Addresses</citetitle></term>
 
265
              <listitem><para/></listitem>
 
266
            </varlistentry>
 
267
            <varlistentry>
 
268
              <term>Section 2.5.5.2: <citetitle>IPv4-Mapped IPv6
 
269
              Address</citetitle></term>
 
270
              <listitem><para/></listitem>
 
271
            </varlistentry>
 
272
            <varlistentry>
 
273
            <term>Section 2.5.6, <citetitle>Link-Local IPv6 Unicast
 
274
            Addresses</citetitle></term>
 
275
            <listitem>
 
276
              <para>
 
277
                The clients use IPv6 link-local addresses, which are
 
278
                immediately usable since a link-local addresses is
 
279
                automatically assigned to a network interface when it
 
280
                is brought up.
 
281
              </para>
 
282
            </listitem>
 
283
            </varlistentry>
 
284
          </variablelist>
 
285
        </listitem>
 
286
      </varlistentry>
 
287
      <varlistentry>
 
288
        <term>
 
289
          <ulink url="http://www.zeroconf.org/">Zeroconf</ulink>
 
290
        </term>
 
291
        <listitem>
 
292
          <para>
 
293
            Zeroconf is the network protocol standard used by clients
 
294
            for finding the Mandos server on the local network.
 
295
          </para>
 
296
        </listitem>
 
297
      </varlistentry>
 
298
    </variablelist>
 
299
  </refsect1>
198
300
</refentry>
 
301
<!-- Local Variables: -->
 
302
<!-- time-stamp-start: "<!ENTITY TIMESTAMP [\"']" -->
 
303
<!-- time-stamp-end: "[\"']>" -->
 
304
<!-- time-stamp-format: "%:y-%02m-%02d" -->
 
305
<!-- End: -->