/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk

« back to all changes in this revision

Viewing changes to INSTALL

  • Committer: Teddy Hogeborn
  • Date: 2018-08-15 09:26:02 UTC
  • Revision ID: teddy@recompile.se-20180815092602-xoyb5s6gf8376i7u
mandos-client: Set system clock if necessary

* plugins.d/mandos-client.c (init_gpgme/import_key): If the system
  clock is not set, or set to january 1970, set the system clock to
  the more plausible value that is the mtime of the key file.  This is
  required by GnuPG to be able to import the keys.  (We can't pass the
  --ignore-time-conflict or the --ignore-valid-from options though
  GPGME.)

Show diffs side-by-side

added added

removed removed

Lines of Context:
39
39
    
40
40
*** Mandos Server
41
41
    + GnuTLS 3.3          https://www.gnutls.org/
42
 
      (but not 3.6.0 or later, until 3.6.6, which works)
43
42
    + Avahi 0.6.16        http://www.avahi.org/
44
43
    + Python 2.7          https://www.python.org/
45
44
    + dbus-python 0.82.4 https://dbus.freedesktop.org/doc/dbus-python/
61
60
    + initramfs-tools 0.85i
62
61
                        https://tracker.debian.org/pkg/initramfs-tools
63
62
    + GnuTLS 3.3        https://www.gnutls.org/
64
 
      (but not 3.6.0 or later, until 3.6.6 which works)
65
63
    + Avahi 0.6.16      http://www.avahi.org/
66
64
    + GnuPG 1.4.9       https://www.gnupg.org/
67
65
    + GPGME 1.1.6       https://www.gnupg.org/related_software/gpgme/
71
69
    + OpenSSH           http://www.openssh.com/
72
70
    
73
71
    Package names:
74
 
    initramfs-tools libgnutls-dev gnutls-bin libavahi-core-dev gnupg
 
72
    initramfs-tools libgnutls-dev libavahi-core-dev gnupg
75
73
    libgpgme11-dev pkg-config ssh
76
74
 
77
75
* Installing the Mandos server
125
123
     
126
124
        # /usr/lib/mandos/plugins.d/mandos-client \
127
125
                --pubkey=/etc/keys/mandos/pubkey.txt \
128
 
                --seckey=/etc/keys/mandos/seckey.txt \
129
 
                --tls-privkey=/etc/keys/mandos/tls-privkey.pem \
130
 
                --tls-pubkey=/etc/keys/mandos/tls-pubkey.pem; echo
 
126
                --seckey=/etc/keys/mandos/seckey.txt; echo
131
127
     
132
128
     This command should retrieve the password from the server,
133
129
     decrypt it, and output it to standard output.