X-Git-Url: https://codewiz.org/gitweb?a=blobdiff_plain;f=etc%2Fmonkeysphere-server.conf;h=85b37c1ead976c6d86b0dca1e2e37dc95301722b;hb=91bf57bac7bed32937c13595044158007e7b5812;hp=bed5c0905fb70b5e4146f2a47c48a4fd2847fa6a;hpb=48cd196efb86f8661fbf77552ef6c26b11fe20c6;p=monkeysphere.git diff --git a/etc/monkeysphere-server.conf b/etc/monkeysphere-server.conf index bed5c09..85b37c1 100644 --- a/etc/monkeysphere-server.conf +++ b/etc/monkeysphere-server.conf @@ -1,23 +1,43 @@ # MonkeySphere server configuration file. +# This is an sh-style shell configuration file. Variable names should +# be separated from their assignements by a single '=' and no spaces. + +#FIXME: shouldn't this be in /var by default? These are not text +#files, and they should generally not be managed directly by the +#admin: # GPG home directory for server #GNUPGHOME=/etc/monkeysphere/gnupg # GPG keyserver to search for keys #KEYSERVER=subkeys.pgp.net -# Required key capabilities +# Required user key capabilities # Must be quoted, lowercase, space-seperated list of the following: # e = encrypt # s = sign # c = certify # a = authentication -#REQUIRED_KEY_CAPABILITY="e a" +#REQUIRED_USER_KEY_CAPABILITY="a" + +# Path to authorized_user_ids file to process to create +# authorized_keys file. '%h' will be replaced by the home directory +# of the user, and %u will be replaced by the username of the user. +# For purely admin-controlled authorized_user_ids, you might put them +# in /etc/monkeysphere/authorized_user_ids/%u +#AUTHORIZED_USER_IDS="%h/.config/monkeysphere/authorized_user_ids" + +#FIXME: why is the following variable named USER_CONTROLLED_...? +#shouldn't this be something like MONKEYSPHERE_RAW_AUTHORIZED_KEYS +#instead? For example, what about a server where the administrator +#has locked down the authorized_keys file from user control, but still +#wants to combine raw authorized_keys for some users with the +#monkeysphere? # Whether to add user controlled authorized_keys file to # monkeysphere-generated authorized_keys file. Should be path to file -# where '%h' will be substituted for the user's home directory. -#USER_CONTROLLED_AUTHORIZED_KEYS=%h/.ssh/authorized_keys - -# where to cache user authorized_keys lines -#STAGING_AREA=/var/lib/monkeysphere/stage +# where '%h' will be replaced by the home directory of the user or +# '%u' by the username. To not add any user-controlled file, put "-" +#FIXME: this usage of "-" contravenes the normal convention where "-" +#means standard in/out. Why not use "none" or "" instead? +#USER_CONTROLLED_AUTHORIZED_KEYS="%h/.ssh/authorized_keys"