Wishlist followup

Lee Winter lee.j.i.winter at gmail.com
Mon Sep 28 01:47:40 CEST 2009


This is a followup to our previous exchange in which I expressed an
interest in having several distinct modes for the control panel.
After further consideration I believe those modes might be useful, but
are not necessary.  Whatever software is interacting with the control
panel should have at least the modes I outlined, but the extra
complexity does not have to be implemented or supported within mandos
itself.

However, an additional consideration has arisen in the form of servers
that need multiple keys to operate.  It would not be hard to envision
a system with dm_crypt under swap, root, home, etc, and another
encryption layer such as aes-loop or truecrypt protecting, /srv or
applied to a particularly sensitive file or directorty.  I just wanted
to confirm that (i) mandos supports aes-loop, truecrypt, or other
LUKS-based tools, and (ii) that mandos will serve multiple keys to a
client as long as each key has a distinct fingerprint.

Are my assumptions valid?

Lee Winter
NP Engineering
Nashua, New Hampshire


More information about the Mandos-Dev mailing list