LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-28-2013, 04:09 AM   #1
sparc86
Member
 
Registered: Jul 2006
Location: Joinville, Brazil
Distribution: Debian, CentOS
Posts: 301

Rep: Reputation: 31
Mandos client doesn't get the passphrase from server


Hi LQ members,

I am trying to implement a mandos environment in my workplace, so the developers can work using encrypt disks without needing to be prompted by the file system passphrase. Well, at least that's what mandos should be all about.

The Mandos documentation is, sadly, quite poor and I can't even establish any communication between the server and the client. And yes, the firewall settings are all right; I have tested manually connecting to the server port using telnet and it works.

So I have created the keys to talk to the server and everything, but then after I reboot the client (expecting it to establish a connection to the server in order to retrieve the passphrase, I get the following errors:

Quote:
Attempting to use OpenPGP public key /etc/keys/mandos/pubkey.txt and secret /etc/keys/mandos/seckey.txt as GnuTLS credentials
GnutLS: ASSERT: gnutls_openpgp.c:479
Error[-64] while reading the OpenPGP key pair ('/etc/keys/mandos/pubkey.txt', '/etc/keys/mandos/seckey.txt')
The GnuTLS error is: Error while reading file.
init_gnutls_global failed
mandos-client exiting

Enter passphrase
Also, I think it is worth mentioning that I have been monitoring all the traffic on the server side (thanks to tcpdump) during the client boot process and I have found no traffic AT ALL related to the mandos protocol and TLS.

So, I would be very thankful if I could get, at least, sample configuration files from anyone here who have successfully deployed mandos.

In the worst case, does anyone here knows and could recommend me a better solution than mandos?

Just in case, here is my "plugin-runner.conf"

Quote:
--options-for=mandos-client:--debug
--options-for=mandos-client:--connect=MyServerIP:42479
--options-for=mandos-client:--pubkey=/etc/keys/mandos/pubkey.txt
--options-for=mandos-client:--pubkey=/etc/keys/mandos/seckey.txt
I'm using Ubuntu 12.04 for the client side and Debian Squeeze for the server side.

Thanks in advance.

References:
https://wiki.recompile.se/wiki/Mandos

Last edited by sparc86; 01-28-2013 at 05:08 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
zmq client server program ..my client is working but server is not..pls help batman4 Programming 2 08-13-2012 07:44 AM
nfs server on ubuntu doesn't play nice with nfs client on solaris mathiraj Linux - Networking 11 09-15-2009 02:08 PM
zeroconf (python): client doesn't get to see the server eantoranz Programming 0 04-13-2009 07:43 PM
Yast doesn't seem to sort out my passphrase correctly bugg_tb SUSE / openSUSE 2 08-14-2006 08:46 PM
KMail and PGP/GPG not working - doesn't ask for passphrase steve1401 Linux - General 2 02-08-2005 06:42 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration