Daniel Kahn Gillmor [Sun, 14 Mar 2010 13:50:57 +0000 (09:50 -0400)]
warn if keyserver query fails (Closes: MS #1750)
Daniel Kahn Gillmor [Sun, 14 Mar 2010 07:06:32 +0000 (03:06 -0400)]
enable use of hkps (closes: MS #1749)
Daniel Kahn Gillmor [Sun, 14 Mar 2010 05:36:57 +0000 (00:36 -0500)]
keys-for-userid now respects MONKEYSPHERE_CHECK_KEYSERVER (Closes: MS #1997); finesse description of CHECK_KEYSERVER in monkeysphere.conf (see: MS #2014)
Daniel Kahn Gillmor [Sun, 14 Mar 2010 04:49:53 +0000 (23:49 -0500)]
clarifying defaults for CHECK_KEYSERVER in monkeysphere.conf
Daniel Kahn Gillmor [Fri, 12 Mar 2010 22:06:39 +0000 (17:06 -0500)]
further consolidating Xsession script
Daniel Kahn Gillmor [Fri, 12 Mar 2010 22:02:16 +0000 (17:02 -0500)]
fixing comment in Xsession script
Daniel Kahn Gillmor [Fri, 12 Mar 2010 22:01:28 +0000 (17:01 -0500)]
add note about dbus communication for msva
Daniel Kahn Gillmor [Fri, 12 Mar 2010 21:53:37 +0000 (16:53 -0500)]
made Xsession script POSIX-compliant, simplified it
Daniel Kahn Gillmor [Fri, 12 Mar 2010 21:47:58 +0000 (16:47 -0500)]
renaming Xsession config file to match existing pattern (underscore only separates package from description)
Daniel Kahn Gillmor [Fri, 12 Mar 2010 07:34:06 +0000 (02:34 -0500)]
installing /etc/X11/Xsession.d/70monkeysphere_use_validation_agent
Daniel Kahn Gillmor [Fri, 12 Mar 2010 07:30:03 +0000 (02:30 -0500)]
documenting USE_VALIDATION_AGENT in configuration
Daniel Kahn Gillmor [Fri, 12 Mar 2010 07:25:07 +0000 (02:25 -0500)]
initialize msva in Xsession based on monkeysphere.conf instead of /etc/X11/Xsession.d
Daniel Kahn Gillmor [Fri, 12 Mar 2010 06:59:06 +0000 (01:59 -0500)]
added new X session validation agent initialization script
Daniel Kahn Gillmor [Wed, 10 Mar 2010 05:29:43 +0000 (00:29 -0500)]
retroactively added notes to changelog for zimmermann
Micah Anderson [Wed, 10 Mar 2010 05:17:35 +0000 (00:17 -0500)]
update zimmermann changelog about minor MS config change to the keyserver
Micah Anderson [Tue, 9 Mar 2010 16:30:20 +0000 (11:30 -0500)]
update george changelog with my changes
Daniel Kahn Gillmor [Tue, 9 Mar 2010 06:22:15 +0000 (01:22 -0500)]
website: link the MSVA protocol back to the overview of the agent
Daniel Kahn Gillmor [Tue, 9 Mar 2010 06:04:56 +0000 (01:04 -0500)]
added website stubs about validation agent
Daniel Kahn Gillmor [Tue, 9 Mar 2010 05:47:48 +0000 (00:47 -0500)]
fixed monkeysphere.7 synopsis to be less ssh-specific
Jameson Rollins [Tue, 9 Mar 2010 04:38:12 +0000 (23:38 -0500)]
Merge remote branch 'mjgoins/master'
Jameson Rollins [Tue, 9 Mar 2010 04:36:45 +0000 (23:36 -0500)]
fix my email address
Matthew James Goins [Tue, 9 Mar 2010 03:07:02 +0000 (22:07 -0500)]
Updated george changelog
Matthew James Goins [Mon, 8 Mar 2010 04:59:26 +0000 (23:59 -0500)]
Changed every inline beginning with [[ to an inline beginning with [[!
Jameson Rollins [Mon, 1 Mar 2010 20:20:07 +0000 (15:20 -0500)]
fix hyphen-used-as-minus-sign man page lint
Daniel Kahn Gillmor [Tue, 23 Feb 2010 20:34:35 +0000 (15:34 -0500)]
more notes on george upgrades: switch to lenny-backports
Daniel Kahn Gillmor [Thu, 18 Feb 2010 23:25:29 +0000 (18:25 -0500)]
allow service names to start with a number (synchronizing with the check in get_port_for_service from common). i know of no services named like that, but why be fussy?
Daniel Kahn Gillmor [Thu, 18 Feb 2010 23:00:51 +0000 (18:00 -0500)]
added explicit bash dependency on version >= 3.2 for modern conditional regex matching
Daniel Kahn Gillmor [Thu, 18 Feb 2010 17:41:43 +0000 (12:41 -0500)]
touching up changelogs as we work toward a 0.29 release.
Daniel Kahn Gillmor [Thu, 18 Feb 2010 17:11:47 +0000 (12:11 -0500)]
enforce --no-armor when exporting to openpgp2ssh in case weird gpg.conf options (see bug 1625)
Daniel Kahn Gillmor [Mon, 8 Feb 2010 19:55:29 +0000 (14:55 -0500)]
initial seminar details -- abstract and feeble outline
Daniel Kahn Gillmor [Sun, 7 Feb 2010 18:18:44 +0000 (13:18 -0500)]
Merge remote branch 'micah/master'
Micah Anderson [Sun, 7 Feb 2010 18:14:31 +0000 (13:14 -0500)]
remove old git documentation
Jameson Rollins [Thu, 4 Feb 2010 17:06:00 +0000 (12:06 -0500)]
fix monkeysphere-authentication man page reference to AuthorizedKeysFile for sshd_config
Jameson Rollins [Thu, 4 Feb 2010 17:00:01 +0000 (12:00 -0500)]
fix changelog about Standards-Version update
Jameson Rollins [Tue, 2 Feb 2010 21:27:31 +0000 (16:27 -0500)]
add some useful shortcuts for some common commands
Daniel Kahn Gillmor [Mon, 1 Feb 2010 06:44:17 +0000 (01:44 -0500)]
bumping debian packaging to Standards-Version 3.8.4 (no changes needed)
Daniel Kahn Gillmor [Tue, 19 Jan 2010 18:59:18 +0000 (13:59 -0500)]
added release note for 0.28
Daniel Kahn Gillmor [Tue, 19 Jan 2010 18:57:27 +0000 (13:57 -0500)]
updating changelogs in preparation for 0.28 release
Daniel Kahn Gillmor [Tue, 19 Jan 2010 16:46:42 +0000 (11:46 -0500)]
actually ship new upstream changelog
Jameson Rollins [Tue, 19 Jan 2010 15:10:17 +0000 (10:10 -0500)]
small man page typo tweak
Daniel Kahn Gillmor [Tue, 19 Jan 2010 08:12:59 +0000 (03:12 -0500)]
Merge remote branch 'jrollins/master'
Daniel Kahn Gillmor [Tue, 19 Jan 2010 08:11:55 +0000 (03:11 -0500)]
re-work monkeysphere-host diagnostics with an eye toward multiple host keys
Daniel Kahn Gillmor [Tue, 19 Jan 2010 08:03:26 +0000 (03:03 -0500)]
dump gpg --import error spew to /dev/null during hackish uses of gpg
Daniel Kahn Gillmor [Tue, 19 Jan 2010 07:36:20 +0000 (02:36 -0500)]
ignoring time conflict when extracting info in a hacky way from gpg. warnings still come out to stderr
Daniel Kahn Gillmor [Tue, 19 Jan 2010 07:01:35 +0000 (02:01 -0500)]
updating utils to deal with the newly split-out changelogs
Daniel Kahn Gillmor [Tue, 19 Jan 2010 06:55:46 +0000 (01:55 -0500)]
switch Makefile to use upstream changelog for versioning info
Daniel Kahn Gillmor [Tue, 19 Jan 2010 06:55:15 +0000 (01:55 -0500)]
updating copyright year in debian postinst packaging
Daniel Kahn Gillmor [Tue, 19 Jan 2010 06:42:34 +0000 (01:42 -0500)]
accepting "--version" as well as "version" subcommand for monkeysphere-host and monkeysphere-authentication
Daniel Kahn Gillmor [Tue, 19 Jan 2010 06:37:14 +0000 (01:37 -0500)]
added a few more FIXMEs to check_service_name()
Daniel Kahn Gillmor [Tue, 19 Jan 2010 06:36:32 +0000 (01:36 -0500)]
add get_cert_info() to common
Daniel Kahn Gillmor [Tue, 19 Jan 2010 04:43:43 +0000 (23:43 -0500)]
removing superfluous eval
Jameson Rollins [Tue, 19 Jan 2010 04:38:14 +0000 (23:38 -0500)]
tweak loading of fingerprints in multi_key wrapper function, so unnecessary error messages aren't output
Daniel Kahn Gillmor [Tue, 19 Jan 2010 04:15:43 +0000 (23:15 -0500)]
no need for recursive removal of a single file
Daniel Kahn Gillmor [Tue, 19 Jan 2010 04:10:42 +0000 (23:10 -0500)]
flesh out check for reasonable-looking service names
Jameson Rollins [Tue, 19 Jan 2010 03:59:26 +0000 (22:59 -0500)]
add 0.28 transition script to generate new host_keys.pub.pgp file, and remove all ssh_host_rsa_key.pub.gpg file
Jameson Rollins [Mon, 18 Jan 2010 23:38:27 +0000 (18:38 -0500)]
canonicalize prompting to prompt if MONKEYSPHERE_PROMPT != 'false'
Jameson Rollins [Mon, 18 Jan 2010 23:22:22 +0000 (18:22 -0500)]
add prompt if a service name is already being used then importing a key or adding a name.
This can be overridden with the MONKEYSPHERE_PROMPT var.
Daniel Kahn Gillmor [Mon, 18 Jan 2010 22:46:12 +0000 (17:46 -0500)]
monkeysphere-host: reverting from host_fingerprints() to list_primary_fingerprints()
Daniel Kahn Gillmor [Mon, 18 Jan 2010 22:28:43 +0000 (17:28 -0500)]
made public use of m-h show-keys instead of show-key, fixed stupid field-numbering bug in fingerprint extraction
Daniel Kahn Gillmor [Mon, 18 Jan 2010 22:14:04 +0000 (17:14 -0500)]
renaming m-h update_gpg_pub_file to update_pgp_pub_file
Daniel Kahn Gillmor [Mon, 18 Jan 2010 22:11:00 +0000 (17:11 -0500)]
renaming host_keys.pub.gpg to host_keys.pub.pgp
Daniel Kahn Gillmor [Mon, 18 Jan 2010 22:07:11 +0000 (17:07 -0500)]
got rid of monkeysphere-host fprs file
Jameson Rollins [Mon, 18 Jan 2010 18:12:00 +0000 (13:12 -0500)]
remove reference to HOST_KEY_FPR_FILE
except in update_gpg_pub_file, which dkg is going to modify to just
hold the host keys and not any other keys (like revoker keys). this
file alone can then be used to get host key info for non-priviledged
users.
Jameson Rollins [Mon, 18 Jan 2010 17:05:37 +0000 (12:05 -0500)]
Merge remote branch 'dkg/master'
Daniel Kahn Gillmor [Mon, 18 Jan 2010 16:54:33 +0000 (11:54 -0500)]
simplified test to cope with possibility of re-ordered keytrans listfprs output
Jameson Rollins [Mon, 18 Jan 2010 16:50:08 +0000 (11:50 -0500)]
suppress superfulous error output
Jameson Rollins [Mon, 18 Jan 2010 16:43:06 +0000 (11:43 -0500)]
add check that service name isn't already in use in import_key
Jameson Rollins [Mon, 18 Jan 2010 16:42:30 +0000 (11:42 -0500)]
fix show_key function to handle user ID input (needed for import_key)
Jameson Rollins [Mon, 18 Jan 2010 15:53:27 +0000 (10:53 -0500)]
fix keytrans test to handle possible permuted output of keytrans listfprs from expected order
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:46:53 +0000 (01:46 -0500)]
wordsmithing debian/control
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:42:52 +0000 (01:42 -0500)]
more tweaks to man pages
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:38:36 +0000 (01:38 -0500)]
Merge remote branch 'jrollins/master'
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:33:11 +0000 (01:33 -0500)]
fix stupid think-o that caused keytrans adduserid to misbehave if another key came in the input stream after the desired key was already found
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:32:08 +0000 (01:32 -0500)]
add check for multiple secret keys and new listfprs subcommand to tests/keytrans
Daniel Kahn Gillmor [Mon, 18 Jan 2010 06:06:50 +0000 (01:06 -0500)]
added non-public "keytrans listfprs" subcommand
Jameson Rollins [Mon, 18 Jan 2010 04:01:35 +0000 (23:01 -0500)]
Merge remote branch 'dkg/master'
Jameson Rollins [Mon, 18 Jan 2010 04:01:29 +0000 (23:01 -0500)]
separate upstream and debian packaging changelogs
Daniel Kahn Gillmor [Mon, 18 Jan 2010 03:23:25 +0000 (22:23 -0500)]
removed unnecessary tmpfile and repetitive keyid extraction from tests/basic
Jameson Rollins [Sat, 16 Jan 2010 18:55:46 +0000 (13:55 -0500)]
update package description
Jameson Rollins [Sat, 16 Jan 2010 18:49:29 +0000 (13:49 -0500)]
some improvements to man pages
Jameson Rollins [Sat, 16 Jan 2010 18:34:51 +0000 (13:34 -0500)]
small tweaks to failure messages
Jameson Rollins [Sat, 16 Jan 2010 18:23:22 +0000 (13:23 -0500)]
tweaks to the monkeysphere-host man page
Jameson Rollins [Sat, 16 Jan 2010 16:57:06 +0000 (11:57 -0500)]
update changelog
Jameson Rollins [Sat, 16 Jan 2010 16:49:18 +0000 (11:49 -0500)]
fix revocation test
was revoking the wrong key for the ssh test. test fully passing now!
Jameson Rollins [Sat, 16 Jan 2010 01:17:15 +0000 (20:17 -0500)]
Try to fix monkeysphere-host and tests/basic for revoke-key test
Unfortunately there's still a problem that I can't quite figure out.
gpg is for some reason failing to import that revocation certificate.
Could it be because gpg can't accept ascii armored certificates as
input? I'm at a loss.
Jameson Rollins [Sat, 16 Jan 2010 00:42:42 +0000 (19:42 -0500)]
Merge remote branch 'dkg/master'
Conflicts:
tests/basic
Jameson Rollins [Sat, 16 Jan 2010 00:37:45 +0000 (19:37 -0500)]
tweaks to tests/basic for new monkeysphere-host ui
Jameson Rollins [Sat, 16 Jan 2010 00:19:15 +0000 (19:19 -0500)]
Major rework of monkeysphere-host to handle multiple host keys.
This rework removes any assumption that monkeysphere-host is just
managing a single host key, or that the keys are used specifically for
ssh. The UI is exactly backwards compatible except that hostnames
('example.com') must be replaced by full service names
('ssh://example.com'). This incarnation passes the old tests with
those changes only.
There are a couple of things that still need to be done:
- need to see if a transition script is needed (some local file names
have changed)
- need to fill in check_service_name function to verify that a
specified service name fits the expected format.
- update diagnostics appropriately
Jameson Rollins [Fri, 15 Jan 2010 23:34:01 +0000 (18:34 -0500)]
add trap to remove temp dir in list_primary_fingerprints function
Daniel Kahn Gillmor [Fri, 15 Jan 2010 19:12:41 +0000 (14:12 -0500)]
adding website page about expanding the monkeysphere
Daniel Kahn Gillmor [Fri, 15 Jan 2010 05:58:22 +0000 (00:58 -0500)]
updating getting-started docs to use the 0.28 monkeysphere-host syntax (specifying full service user ID including scheme)
Daniel Kahn Gillmor [Fri, 15 Jan 2010 05:47:19 +0000 (00:47 -0500)]
overhaul monkeysphere-host(8) to match new multi-key capable interface
Daniel Kahn Gillmor [Fri, 15 Jan 2010 04:13:35 +0000 (23:13 -0500)]
added missing openssl.cnf for test suite.
Daniel Kahn Gillmor [Fri, 15 Jan 2010 04:11:53 +0000 (23:11 -0500)]
update monkeysphere-authentication(8) to acknowledge use of monkeysphere beyond OpenSSH
Daniel Kahn Gillmor [Fri, 15 Jan 2010 04:10:58 +0000 (23:10 -0500)]
update monkeysphere(1) to acknowledge use beyond OpenSSH
Daniel Kahn Gillmor [Fri, 15 Jan 2010 03:27:21 +0000 (22:27 -0500)]
added simple basic test for second key for monkeysphere-host, pulled this time from OpenSSL
Daniel Kahn Gillmor [Fri, 15 Jan 2010 03:23:05 +0000 (22:23 -0500)]
changed test suite variable from HOSTKEY to SSHHOSTKEY; updated path to exported host keys (from ssh_host_rsa_key.pub.gpg to host_keys.gpg.pub)
Daniel Kahn Gillmor [Fri, 15 Jan 2010 02:33:55 +0000 (21:33 -0500)]
updating test suite to new preferred "monkeysphere-host {add,revoke}-servicename" subcommand
Daniel Kahn Gillmor [Fri, 15 Jan 2010 02:20:35 +0000 (21:20 -0500)]
updated test suite to use scheme://hostname instead of raw hostname, in preparation for multi-key monkeysphere-host
Daniel Kahn Gillmor [Fri, 15 Jan 2010 02:18:56 +0000 (21:18 -0500)]
added test of "monkeysphere keys-for-userid"