/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to plugins.d/password-prompt.xml

  • Committer: Teddy Hogeborn
  • Date: 2017-08-20 14:14:14 UTC
  • Revision ID: teddy@recompile.se-20170820141414-m034xuebg7ccaeui
Add some more restrictions to the systemd service file.

* mandos.service ([Service]/ProtectKernelTunables): New; set to "yes".
  ([Service]/ProtectControlGroups): - '' -

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
1
<?xml version="1.0" encoding="UTF-8"?>
2
2
<!DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3
3
        "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4
 
<!ENTITY VERSION "1.0">
5
4
<!ENTITY COMMANDNAME "password-prompt">
6
 
<!ENTITY TIMESTAMP "2008-09-01">
 
5
<!ENTITY TIMESTAMP "2017-02-23">
 
6
<!ENTITY % common SYSTEM "../common.ent">
 
7
%common;
7
8
]>
8
9
 
9
10
<refentry xmlns:xi="http://www.w3.org/2001/XInclude">
11
12
    <title>Mandos Manual</title>
12
13
    <!-- NWalsh’s docbook scripts use this to generate the footer: -->
13
14
    <productname>Mandos</productname>
14
 
    <productnumber>&VERSION;</productnumber>
 
15
    <productnumber>&version;</productnumber>
15
16
    <date>&TIMESTAMP;</date>
16
17
    <authorgroup>
17
18
      <author>
18
19
        <firstname>Björn</firstname>
19
20
        <surname>Påhlsson</surname>
20
21
        <address>
21
 
          <email>belorn@fukt.bsnet.se</email>
 
22
          <email>belorn@recompile.se</email>
22
23
        </address>
23
24
      </author>
24
25
      <author>
25
26
        <firstname>Teddy</firstname>
26
27
        <surname>Hogeborn</surname>
27
28
        <address>
28
 
          <email>teddy@fukt.bsnet.se</email>
 
29
          <email>teddy@recompile.se</email>
29
30
        </address>
30
31
      </author>
31
32
    </authorgroup>
32
33
    <copyright>
33
34
      <year>2008</year>
 
35
      <year>2009</year>
 
36
      <year>2010</year>
 
37
      <year>2011</year>
 
38
      <year>2012</year>
 
39
      <year>2013</year>
 
40
      <year>2014</year>
 
41
      <year>2015</year>
 
42
      <year>2016</year>
 
43
      <year>2017</year>
34
44
      <holder>Teddy Hogeborn</holder>
35
45
      <holder>Björn Påhlsson</holder>
36
46
    </copyright>
83
93
    <title>DESCRIPTION</title>
84
94
    <para>
85
95
      All <command>&COMMANDNAME;</command> does is prompt for a
86
 
      password and output any given password to standard output.  This
87
 
      is not very useful on its own.  This program is really meant to
88
 
      run as a plugin in the <application>Mandos</application>
89
 
      client-side system, where it is used as a fallback and
90
 
      alternative to retriving passwords from a <application
91
 
      >Mandos</application> server.
 
96
      password and output any given password to standard output.
 
97
    </para>
 
98
    <para>
 
99
      This program is not very useful on its own.  This program is
 
100
      really meant to run as a plugin in the <application
 
101
      >Mandos</application> client-side system, where it is used as a
 
102
      fallback and alternative to retrieving passwords from a
 
103
      <application >Mandos</application> server.
92
104
    </para>
93
105
    <para>
94
106
      This program is little more than a <citerefentry><refentrytitle
179
191
    <title>ENVIRONMENT</title>
180
192
    <variablelist>
181
193
      <varlistentry>
182
 
        <term><envar>cryptsource</envar></term>
183
 
        <term><envar>crypttarget</envar></term>
 
194
        <term><envar>CRYPTTAB_SOURCE</envar></term>
 
195
        <term><envar>CRYPTTAB_NAME</envar></term>
184
196
        <listitem>
185
197
          <para>
186
198
            If set, these environment variables will be assumed to
215
227
  
216
228
  <refsect1 id="bugs">
217
229
    <title>BUGS</title>
218
 
    <para>
219
 
      None are known at this time.
220
 
    </para>
 
230
    <xi:include href="../bugs.xml"/>
221
231
  </refsect1>
222
232
  
223
233
  <refsect1 id="example">
240
250
      <para>
241
251
        Show a prefix before the prompt; in this case, a host name.
242
252
        It might be useful to be reminded of which host needs a
243
 
        password, in case of KVM switches, etc.
 
253
        password, in case of <acronym>KVM</acronym> switches, etc.
244
254
      </para>
245
255
      <para>
246
256
 
270
280
      >plugin-runner</refentrytitle><manvolnum>8mandos</manvolnum>
271
281
      </citerefentry>, and will, when run standalone, outside, in a
272
282
      normal environment, immediately output on its standard output
273
 
      any presumably secret password it just recieved.  Therefore,
 
283
      any presumably secret password it just received.  Therefore,
274
284
      when running this program standalone (which should never
275
285
      normally be done), take care not to type in any real secret
276
286
      password by force of habit, since it would then immediately be
288
298
  <refsect1 id="see_also">
289
299
    <title>SEE ALSO</title>
290
300
    <para>
 
301
      <citerefentry><refentrytitle>intro</refentrytitle>
 
302
      <manvolnum>8mandos</manvolnum></citerefentry>
291
303
      <citerefentry><refentrytitle>crypttab</refentrytitle>
292
304
      <manvolnum>5</manvolnum></citerefentry>
293
 
      <citerefentry><refentrytitle>password-request</refentrytitle>
 
305
      <citerefentry><refentrytitle>mandos-client</refentrytitle>
294
306
      <manvolnum>8mandos</manvolnum></citerefentry>
295
307
      <citerefentry><refentrytitle>plugin-runner</refentrytitle>
296
308
      <manvolnum>8mandos</manvolnum></citerefentry>,