Age | Commit message (Collapse) | Author | |
---|---|---|---|
2010-10-22 | tweak log levels and messages in ma/update_users | Jameson Rollins | |
2010-10-19 | fix remove_line function to not use fixed string checking, and to mv -f the ↵ | Jameson Rollins | |
tmp file into place | |||
2010-10-18 | fix remove_monkeysphere_lines function to just read from stdin and write to ↵ | Jameson Rollins | |
stdout | |||
2010-10-18 | fix update_known_hosts to create proper initial temp file | Jameson Rollins | |
2010-10-18 | fix back to integer indexing in process_authorized_user_ids | Jameson Rollins | |
2010-10-18 | cleanup update_known_hosts | Jameson Rollins | |
* don't update if unchanged * proper trap setting * cleanup comments | |||
2010-10-18 | fix up update_authorized_keys | Jameson Rollins | |
* better trap handling * don't update file if unchanged * clean up comments | |||
2010-10-18 | fix process_keys_for_file so that it can accept '-' as a file, and send ↵ | Jameson Rollins | |
output to stdout. | |||
2010-10-18 | Simplification/refactoring of key/file processing | Jameson Rollins | |
This is a fairly major overhaul to greatly reduce the number of redundant code paths. We here created a new process_keys_for_file function that processes key from a userid for a given key file. All the main top elevel functions now call this one function. The main top level monkeysphere functions for updating the user's authorized_keys and known_hosts files are now moved to their own sourced files, which greatly reduces the amount of code sourced with common. monkeysphere now updates authorized_keys and known_hosts in temporary files that are then atomically moved into place upon completion. Finally, removed the confusing return codes in the key/file processing functions that were based on number of valid/invalid keys processed. It was confusing in the presence of actual errors that stopped processing. | |||
2010-10-18 | add check for argument in keys-for-user | Jameson Rollins | |
2010-10-17 | fixed bug in remove_monkeysphere_lines function | Jameson Rollins | |
it was matching MonkeySphere strings as full lines and therefore not actually removing monkeysphere lines. I'm not sure exactly why, upon further consideration, why we actually need to be removing all monkeysphere lines in update_authorized_keys. | |||
2010-10-17 | remove unneccessary export of TMP_AUTHORIZED_USER_IDS | Jameson Rollins | |
2010-10-17 | fix keys-for-user | Jameson Rollins | |
This function now properly outputs to stdout exactly what would have been written to the monkeysphere-controlled authorized_keys file, but without actually touching it. | |||
2010-10-17 | add 'k' as shortcut for keys-for-user | Jameson Rollins | |
2010-10-17 | fix typo in monkeysphere usage | Jameson Rollins | |
2010-10-15 | make sure authorized_keys options lines are skipped in keys-for-user | Jameson Rollins | |
2010-10-15 | attempt to fix apostroproblem in ma/keys-for-user | Jameson Rollins | |
This is an attempt to fix #600304 by properly passing the string litteral in to be processed, instead of escaping problematic characters. | |||
2010-10-08 | default HASH_KNOWN_HOSTS to false (closes MS #2483) | Daniel Kahn Gillmor | |
2010-10-06 | Fix more calls to gpg_shere, finishing what was started in ↵ | Jameson Rollins | |
90166e0bb8e4ebc1c1174d9bc2021c604b7a1bd7 There were another calls to gpg_sphere that were packing everything into a single argument. Since we fixed the need to do that, we fix all these other calls that were fixed in the first round. | |||
2010-10-04 | use LC_ALL=C for all gpg calls | Jameson Rollins | |
This should help with internationalization differences in gpg that could cause problems. Works in tests as is, but haven't tested with odd locales. | |||
2010-10-04 | fix need for only single argument to gpg_sphere | Jameson Rollins | |
The use of $* instead of $@ in the call to su_monkeysphere_user is what we want to not split the input to the bash subcalls into separate words. | |||
2010-10-03 | Merge remote branch 'jrollins/master' | Daniel Kahn Gillmor | |
2010-10-02 | fix formatting of b3f0bbedbf242d2640d3bc56cce62ae726081400 to conform to ↵ | Jameson Rollins | |
standard | |||
2010-10-02 | add debugging to monkeysphere-host publish-key, closes: #2289 | Micah Anderson | |
2010-10-02 | Assume that space- or tab-prefixed lines contain ssh authorized_keys options ↵ | Clint Adams | |
applicable to the preceding user ID. | |||
2010-10-01 | fix revoke_key typo in creating temporary directory | Micah Anderson | |
fix variable specifying which key to revoke monkeysphere-host revoke-key <key-id> would produce the following errors, this commit fixes that: Really publish this cert to zimmermann.mayfirst.org ? (Y/n) y /usr/share/monkeysphere/mh/revoke_key: line 96: mkmstempdir: command not found gpg: new configuration file `/root/.gnupg/gpg.conf' created gpg: WARNING: options in `/root/.gnupg/gpg.conf' are not yet active during this run gpg: "0x!" not a key ID: skipping | |||
2010-09-21 | Merge remote branch 'jamie/master' | Daniel Kahn Gillmor | |
2010-09-21 | change log level for outputting message: "! primary key could not be | Jamie McClelland | |
translated (not RSA?)." from "error" to "verbose" | |||
2010-09-14 | fix *all* install paths, including in man pages and transition scripts | Jameson Rollins | |
2010-09-14 | fix specification of install directories in top level scripts. | Jameson Rollins | |
Various install paths were hard coded in the top level scripts. This was causing problems for non-standard install locations. Also added use of LOCALSTATEDIR variable to specify /var/lib path. | |||
2010-07-04 | Merge remote branch 'dkg/master' | Jameson Rollins | |
2010-07-04 | fix debug message in checkperms | Jameson Rollins | |
2010-07-04 | add keys-for-user subcommand to monkeysphere-authentication | Jameson Rollins | |
This subcommand will output all valid key for a given user. The user's authorized_user_ids file will be read for OpenPGP user IDs, one per line. The ssh-formated RSA keys will be output to stdout. Also included is a simple script that takes the user as it's one argument and exec's this command. This is something that would be suitable for the proposed sshd AuthorizedKeysCommand. | |||
2010-05-06 | reporting new expiration date when key expiry is updated (closes MS #2291) | Daniel Kahn Gillmor | |
2010-05-06 | do not fail or bail when admin interactively declines to publish a key with m-h | Daniel Kahn Gillmor | |
2010-05-06 | support x509 anchors for monkeysphere-host, allow shared anchors between m-a ↵ | Daniel Kahn Gillmor | |
and mh (closes MS #2288) | |||
2010-04-17 | do not try to add to known_hosts if HASH_KNOWN_HOSTS is true but ssh-keygen ↵ | Daniel Kahn Gillmor | |
is not available (includes some comments about how to fix these corner cases). | |||
2010-04-17 | degrade gracefully in the absence of ssh | Daniel Kahn Gillmor | |
2010-04-17 | handling ssh fingerprinting internally with keytrans for sshfprs-for-userid | Daniel Kahn Gillmor | |
2010-04-17 | make comment more nit-pickingly accurate | Daniel Kahn Gillmor | |
2010-04-17 | fix gpg_ssh_fingerprint() in monkeysphere to use internal implementation of ↵ | Daniel Kahn Gillmor | |
ssh fingerprinting | |||
2010-04-17 | monkeysphere-host no longer depends on ssh | Daniel Kahn Gillmor | |
2010-04-17 | keytrans openpgp2sshfpr now prints out the key size and type | Daniel Kahn Gillmor | |
2010-04-17 | added internal openpgp2sshfpr subcommand for keytrans | Daniel Kahn Gillmor | |
2010-03-14 | added comment about why the key file is named with whitespace | Daniel Kahn Gillmor | |
2010-03-14 | deprecate sshfpr; add sshfprs-for-userid (closes: MS #1436) | Daniel Kahn Gillmor | |
2010-03-14 | use msmktempfile instead of raw mktemp -- should be more portable | Daniel Kahn Gillmor | |
2010-03-14 | fix CHECK_KEYSERVER for deprecated keys-from-userid as well | Daniel Kahn Gillmor | |
2010-03-14 | fix typo | Daniel Kahn Gillmor | |
2010-03-14 | avoid checking trustdb from monkeysphere-host (Closes: MS #1957) | Daniel Kahn Gillmor | |