/mandos/trunk

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/trunk
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
1
-*- org -*-
2
418 by teddy at bsnet
* TODO: Clarifications.
3
* Use _attribute_((nonnull)) wherever possible.
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
4
171 by Teddy Hogeborn
Renamed "password-request" to "mandos-client".
5
* mandos-client
355 by Teddy Hogeborn
* mandos: White-space fixes only.
6
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
7
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
8
** TODO use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
9
** TODO [#B] Retry a server which has a non-definite reply:
363 by Teddy Hogeborn
* plugin-runner.c: Minor stylistic changes.
10
*** A closed connection during the TLS handshake
11
*** A TCP timeout
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
12
** TODO [#B] Use capabilities instead of seteuid().
413 by Teddy Hogeborn
TODO file changes.
13
** TODO [#A] Retry --connect forever
355 by Teddy Hogeborn
* mandos: White-space fixes only.
14
15
* splashy
16
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
17
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
18
** TODO [#B] use error() instead of perror()
355 by Teddy Hogeborn
* mandos: White-space fixes only.
19
20
* usplash
414 by Teddy Hogeborn
Bug fix: mandos-client needs GnuPG but lacked a dependency on it. The
21
** TODO [#A] Make it work again
355 by Teddy Hogeborn
* mandos: White-space fixes only.
22
** TODO [#B] use scandir(3) instead of readdir(3)
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
23
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
24
** TODO [#B] use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
25
26
* askpass-fifo
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
27
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
28
** TODO [#B] use error() instead of perror()
365 by Teddy Hogeborn
* plugins.d/mandos-client.c (main): Bug fix: Check result of setgid().
29
** TODO [#B] Drop privileges after opening FIFO.
358 by Teddy Hogeborn
* plugins.d/mandos-client.c (start_mandos_communication): Check
30
31
* password-prompt
389 by Teddy Hogeborn
* plugins.d/splashy.c: Use exit codes from <sysexits.h>.
32
** TODO [#B] Prefix all debug output with "Mandos plugin " + program_invocation_short_name
413 by Teddy Hogeborn
TODO file changes.
33
** TODO [#B] use error() instead of perror()
34
** TODO [#B] lock stdin (with flock()?)
355 by Teddy Hogeborn
* mandos: White-space fixes only.
35
413 by Teddy Hogeborn
TODO file changes.
36
* TODO [#B] passdev
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
37
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
38
* plugin-runner
39
** TODO [#B] use scandir(3) instead of readdir(3)
344 by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1".
40
** TODO [#C] use same file name rules as run-parts(8)
24.1.145 by Björn Påhlsson
todo
41
** kernel command line option for debug info
413 by Teddy Hogeborn
TODO file changes.
42
** TODO [#B] use error() instead of perror()
418 by teddy at bsnet
* TODO: Clarifications.
43
** TODO [#B] Use openat()
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
44
87 by Teddy Hogeborn
* Makefile: Bug fix: fixed creation of man pages in "plugins.d".
45
* mandos (server)
413 by Teddy Hogeborn
TODO file changes.
46
** TODO [#B] Log level							  :BUGS:
47
** TODO Persistent state						  :BUGS:
48
   /var/lib/mandos/*
49
*** TODO /etc/mandos/clients.d/*.conf
50
    Watch this directory and add/remove/update clients?
51
** TODO [#C] config for TXT record
52
** TODO Log level option
53
   syslogger.setLevel(logging.WARNING)
54
   + SetLogLevel D-Bus call
55
** TODO Implement --foreground						  :BUGS:
182 by Teddy Hogeborn
* Makefile (install): Use "install-client-nokey".
56
   [[info:standards:Option%20Table][Table of Long Options]]
57
** TODO Implement --socket
58
   [[info:standards:Option%20Table][Table of Long Options]]
413 by Teddy Hogeborn
TODO file changes.
59
** TODO Date+time on console log messages				  :BUGS:
64 by Teddy Hogeborn
* mandos-client.c (print_out_password): Strip trailing '\n'.
60
   Is this the default?
413 by Teddy Hogeborn
TODO file changes.
61
** TODO [#C] DBusServiceObjectUsingSuper
62
** TODO [#B] Global enable/disable flag
63
** TODO [#B] By-client countdown on secrets given
64
** TODO [#B] Fix problem with fsck taking a really long time
367 by Teddy Hogeborn
* init.d-mandos: Bug fix: Correct the LSB header.
65
   Whenever a client successfully gets a secret it could get a
66
   one-time timeout boost to allow for an fsck-incurred delay
413 by Teddy Hogeborn
TODO file changes.
67
** TODO [#A] Delay before client receives key
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
68
   This would give an operator opportunity to cancel the request if
69
   desired.
413 by Teddy Hogeborn
TODO file changes.
70
** TODO [#A] Client manual approval mode
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
71
   A client needs manual approval on the server before it gets the
72
   secret
413 by Teddy Hogeborn
TODO file changes.
73
** TODO [#B] Support RFC 3339 time duration syntax
416.1.1 by Teddy Hogeborn
Initial design on approval system.
74
** More D-Bus methods
75
*** NeedsApproval(50, True) -> timeout, default approve
76
    Default approval is configurable, but True by default
418 by teddy at bsnet
* TODO: Clarifications.
77
    + Approve(True) -> approve sending saved
78
    + Approve(False) -> Close client connection immediately
416.1.1 by Teddy Hogeborn
Initial design on approval system.
79
*** NeedsPassword(50) - Timeout, default disapprove
80
    + SetPass(u"gazonk", True) -> Approval, persistent
418 by teddy at bsnet
* TODO: Clarifications.
81
    + Approve(False) -> Close client connection immediately
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
82
** TODO [#C] python-parsedatetime
83
** TODO [#C] systemd/launchd
84
   http://0pointer.de/blog/projects/systemd.html
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
85
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
86
* mandos.xml
87
** [[file:mandos.xml::XXX][Document D-Bus interface]]
413 by Teddy Hogeborn
TODO file changes.
88
   Remove mention of lack of such interface in BUGS section
24.1.143 by Björn Påhlsson
added documentation todo
89
** Add mandos contact info in manual pages
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
90
413 by Teddy Hogeborn
TODO file changes.
91
* TODO [#A] Provide and install /etc/dbus-1/system.d/mandos.conf
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
92
308 by Teddy Hogeborn
* plugin-runner.c: Comment change.
93
* mandos-ctl
243 by Teddy Hogeborn
* mandos (Client.timeout, Client.interval): Changed from being a
94
*** Handle "no D-Bus server" and/or "no Mandos server found" better
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
95
*** [#B] --dump option
411 by Teddy Hogeborn
More consistent terminology: Clients are no longer "invalid" - they
96
** TODO Support RFC 3339 time duration syntax
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
97
377 by Teddy Hogeborn
* plugins.d/password-prompt.c (main): Fix "-Wconversion" warning.
98
* TODO mandos-dispatch
99
  Listens for specified D-Bus signals and spawns shell commands with
100
  arguments.
101
375 by Teddy Hogeborn
* TODO: Updated.
102
* mandos-monitor
386 by Teddy Hogeborn
* mandos (DBusObjectWithProperties.Introspect): Add the name
103
** Urwid client data displayer
413 by Teddy Hogeborn
TODO file changes.
104
   Better view of client data in the listing
327 by Teddy Hogeborn
Merge from pipe IPC branch.
105
*** Properties popup
240 by Teddy Hogeborn
Merge "mandos-list" from belorn.
106
228 by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network
107
* mandos-keygen
24.1.126 by Björn Påhlsson
small stuff
108
** TODO Loop until passwords match when run interactively
228 by Teddy Hogeborn
* INSTALL: Add instructions on how to set the correct network
109
** TODO "--secfile" option
110
   Using the "secfile" option instead of "secret"
111
** TODO [#B] "--test" option
112
   For testing decryption before rebooting.
67 by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on
113
370 by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3".
114
* Makefile
416.1.2 by Teddy Hogeborn
* mandos (ClientHandler.handle): Set up the GnuTLS session object
115
** TODO Add "--Xlinker --as-needed"
116
   http://udrepper.livejournal.com/19395.html
413 by Teddy Hogeborn
TODO file changes.
117
** TODO [#C] Implement DEB_BUILD_OPTIONS
370 by Teddy Hogeborn
* debian/control (Standards-Version): Updated to "2.8.3".
118
   http://www.debian.org/doc/debian-policy/ch-source.html#s-debianrules-options
119
275 by Teddy Hogeborn
* debian/mandos-client.postinst: Converted to Bourne shell. Also
120
* Package
67 by Teddy Hogeborn
* mandos-keygen: New program to generate new client keys on
121
** /usr/share/initramfs-tools/hooks/mandos
344 by Teddy Hogeborn
* debian/control (Standards-Version): Changed to "3.8.1".
122
*** TODO [#C] use same file name rules as run-parts(8)
263 by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and
123
*** TODO [#C] Do not install in initrd.img if configured not to.
308 by Teddy Hogeborn
* plugin-runner.c: Comment change.
124
    Use "/etc/initramfs-tools/hooksconf.d/mandos"?
263 by Teddy Hogeborn
* README (The Plugin System): Removed redundant text about options and
125
** TODO [#C] /etc/bash_completion.d/mandos
88 by Teddy Hogeborn
No code or documentation changes.
126
   From XML sources directly?
24.1.30 by Björn Påhlsson
Added more stuff to do
127
36 by Teddy Hogeborn
* TODO: Converted to org-mode style
128

129
#+STARTUP: showall