summaryrefslogtreecommitdiff
path: root/doc/TODO
blob: 6006d628b5820b4a5681800380fd25c0c25d3b75 (plain)
  1. Next-Steps Monkeysphere Projects:
  2. ---------------------------------
  3. Detail advantages of monkeysphere: detail the race conditions in ssh,
  4. and how the monkeysphere can help you reduce these threat vectors:
  5. threat model reduction diagrams.
  6. Handle unverified monkeysphere hosts in such a way that they're not
  7. always removed from known_hosts file. Ask user to lsign the host
  8. key?
  9. Work out the details (and describe a full use case) for assigning a
  10. REVOKER during monkeysphere-server gen_key -- how is this set? How
  11. do we export it so it's available when a second-party revocation is
  12. needed?
  13. Actually enable server hostkey publication.
  14. Streamline host key generation, publication, verification. See
  15. doc/george/host-key-publication for what dkg went through on
  16. 2008-06-19
  17. Ensure that authorized_user_ids are under as tight control as ssh
  18. expects from authorized_keys: we don't want monkeysphere to be a
  19. weak link in the filesystem.
  20. Consider the default permissions for
  21. /var/lib/monkeysphere/authorized_keys/* (and indeed the whole
  22. directory path leading up to that)
  23. Make sure alternate ports are handled for known_hosts.
  24. Script to import private key into ssh agent.
  25. Provide a friendly interactive UI for marginal or failing client-side
  26. hostkey verifications. Handle the common cases smoothly, and
  27. provide good debugging info for the unusual cases.
  28. Make sure onak properly escapes user IDs with colons in them.
  29. Indicate on web site how to report trouble or concerns, and how to
  30. join the project.
  31. Clean up the style for the web site (pages, icons, etc).
  32. Create ssh2openpgp or convert to full-fledged keytrans.
  33. Resolve the bugs listed in openpgp2ssh(1):BUGS.
  34. Understand and document alternate trustdb models.
  35. Understand and document the output of gpg --check-trustdb:
  36. gpg: 3 marginal(s) needed, 1 complete(s) needed, PGP trust model
  37. gpg: depth: 0 valid: 2 signed: 20 trust: 0-, 0q, 0n, 0m, 0f, 2u
  38. gpg: depth: 1 valid: 20 signed: 67 trust: 15-, 0q, 1n, 3m, 1f, 0u
  39. gpg: next trustdb check due at 2008-10-09
  40. Understand and document the numeric values between sig! and the keyid
  41. in "gpg --check-sigs $KEYID" . Compare with the details found from
  42. "gpg --with-colons --check-sigs $KEYID". This has to do with trust
  43. signatures.
  44. Fix gpg's documentation to clarify the difference between validity and
  45. ownertrust. Include better documentation for trust signatures.
  46. Make it easier to do domain-relative ssh host trust signatures with
  47. gnupg. (e.g. "i trust Jamie McClelland (keyID 76CC057D) to properly
  48. identify ssh servers in the mayfirst.org domain") See:
  49. http://tools.ietf.org/html/rfc4880#section-5.2.3.21 and grep for
  50. "tsign" in gpg(1).
  51. Fix the order of questions when user does a tsign in gpg or gpg2.
  52. File bug against ssh-keygen about how "-R" option removes comments
  53. from known_hosts file.
  54. File bug against ssh-keygen to see if we can get it to write to hash a
  55. known_hosts file to/from stdout/stdin.
  56. When using ssh-proxycommand, if only host keys found are expired or
  57. revoked, then output loud warning with prompt, or fail hard.
  58. File bug against seahorse about how, when creating new primary keys,
  59. it presents option for "RSA (sign only)" but then creates an "esca"
  60. key.
  61. File bug against enigmail about lack of ability to create subkeys.
  62. Test and document what happens when any filesystem that the
  63. monkeysphere-server relies on and modifies (/tmp, /etc, and /var?)
  64. fills up.
  65. Optimize keyserver access, particularly on monkeysphere-server
  66. update-users -- is there a way to query the keyserver all in a
  67. chunk?
  68. Create DSA authentication subkey for server during gen-key
  69. Fix behavior when add-identity-certifier fails to fetch a key from the
  70. keyserver.
  71. Allow server administrators to add-identity-certifier from a key in
  72. the filesystem (or on stdin, etc)
  73. Add "monkeysphere-server diagnostics" subcommand to identify missing
  74. pieces of monkeysphere server administration setup.