Re: Patch: wtls userguide
Nikos Balkanas <[email protected]>
| Newsgroups | gmane.comp.mobile.kannel.devel |
|---|---|
| Message-ID | <CAAxXO2HReJS-ROd-JKvPiE+7hwJ72Z9Tz2E4DWw6EDNu-Yb2Lg@mail.gmail.com> |
Hi Alex, I corrected everything by the eye using the docbook dtd and your error reporting. I fixed all the errors in your report. It seems to me valid by the dtd, however, I don't know how it looks (nested ordered lists). I was not able to validate, since a docbook validator would seriously change my environment. BR, Nikos On Sat, Aug 6, 2011 at 12:03 AM, Nikos Balkanas <[email protected]> wrote: > My apologies for that. It is very difficult to build a docbook environment > in Solaris. I have already fixed manually one problem in nested lists from > the dtd, and have downloaded some docbook viewers for windows. As soon as i > get the (free) licenses for them and verify the patch, I will submit again. > > BR, > Nikos > > On Fri, Aug 5, 2011 at 11:52 AM, Alexander Malysh <[email protected]>wrote: > >> Hi Nikos, >> >> could you please check your patch because it produce errors: >> >> jade:doc/userguide/userguide.tmp:2253:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2253:31:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2254:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2254:32:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2255:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2255:32:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2256:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2256:37:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2257:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2257:32:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2258:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2258:32:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2259:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2259:37:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2263:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2263:36:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2268:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2268:36:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2269:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2269:36:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2270:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2270:33:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2271:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2271:33:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2272:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2272:36:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2276:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2276:35:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2277:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2277:44:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2278:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2278:37:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2279:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2279:37:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2280:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2280:34:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2285:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2285:34:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2289:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2289:38:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2290:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2290:38:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2291:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2291:37:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2292:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2292:33:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2293:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2293:33:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2294:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2294:35:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2295:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2295:39:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2296:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2296:39:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2297:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2297:44:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2306:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2306:53:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2307:16:E: character data is not allowed >> here >> jade:doc/userguide/userguide.tmp:2309:53:E: end tag for "LISTITEM" which >> is not finished >> jade:doc/userguide/userguide.tmp:2363:7:E: end tag for "TBODY" omitted, >> but OMITTAG NO was specified >> jade:doc/userguide/userguide.tmp:2339:2: start tag was here >> jade:doc/userguide/userguide.tmp:2363:7:E: end tag for "TGROUP" omitted, >> but OMITTAG NO was specified >> jade:doc/userguide/userguide.tmp:2331:2: start tag was here >> jade:doc/userguide/userguide.tmp:2363:7:E: end tag for "TABLE" omitted, >> but OMITTAG NO was specified >> jade:doc/userguide/userguide.tmp:2329:1: start tag was here >> make: *** [doc/userguide/userguide.html] Error 1 >> >> Am 02.08.2011 um 21:15 schrieb Nikos Balkanas: >> >> > Gladly, here you go ;-) >> > >> > Nikos >> > ----- Original Message ----- From: "Alexander Malysh" < >> [email protected]> >> > To: "Nikos Balkanas" <[email protected]> >> > Cc: "Kannel Devel" <[email protected]> >> > Sent: Tuesday, August 02, 2011 12:31 PM >> > Subject: Re: Patch: wtls userguide >> > >> > >> >> Hi Nikos, >> >> >> >> sorry I missed this patch. Could you please resend? >> >> >> >> Thanks, >> >> Alex >> >> >> >> Am 31.07.2011 um 00:13 schrieb Nikos Balkanas: >> >> >> >>> Hi Alex, >> >>> >> >>> Any news? >> >>> >> >>> Nikos >> >>> ----- Original Message ----- From: "Nikos Balkanas" < >> [email protected]> >> >>> To: "Alexander Malysh" <[email protected]> >> >>> Cc: <[email protected]>; "Armindo Antunes" <[email protected]> >> >>> Sent: Friday, July 22, 2011 3:37 PM >> >>> Subject: Re: Patch: wtls userguide >> >>> >> >>> >> >>>> Hi, >> >>>> >> >>>> This is an update. Forgot listing of supported ciphers. Maybe it >> should go >> >>>> to an Appendix. What do you think? >> >>>> >> >>>> BR, >> >>>> Nikos >> >>>> ----- Original Message ----- From: "Nikos Balkanas" < >> [email protected]> >> >>>> To: "Alexander Malysh" <[email protected]> >> >>>> Cc: <[email protected]>; "Armindo Antunes" <[email protected] >> > >> >>>> Sent: Friday, July 22, 2011 12:39 AM >> >>>> Subject: Patch: wtls userguide >> >>>> >> >>>> >> >>>>> Hi Alex, >> >>>>> >> >>>>> A long overdue wtls section for the userguide. Adds another section >> for >> >>>>> wtls >> >>>>> and another Appendix for certificate generation. >> >>>>> >> >>>>> BR, >> >>>>> Nikos >> >>>>> >> >>> >> > <userguide.diff> >> >> >
userguide.diff
(application/octet-stream, 8.1 KB)
Index: doc/userguide/userguide.xml
===================================================================
--- doc/userguide/userguide.xml (revision 4916)
+++ doc/userguide/userguide.xml (working copy)
@@ -2238,82 +2238,74 @@
<chapter id="wtls">
<title>Setting up wtls security</title>
- <para>This chapter tells you how to set Kannel up to handle wtls traffic.</para>
+ <para>This chapter tells you how to set Kannel up to handle wtls traffic.
+ </para>
- <para><literal>wtls</literal> group is optional and single. The prerequisites for this group
+ <para>'wtls' group is optional and single. The prerequisites for this group
are to have defined a wapbox group, and a pair of SSL certificates
available. Instructions on how to create self-signed 1024-bit RSA
certificates are in Appendix B.
</para>
<para>Current imlementation provides for the following functionality:</para>
<para>
- <itemizedlist>
- <listitem><para>A) Supported MACs:</para>
- <para><itemizedlist>
- <listitem>SHA_0</listitem>
- <listitem>SHA_40</listitem>
- <listitem>SHA_80</listitem>
- <listitem>SHA_NOLIMIT</listitem>
- <listitem>MD5_40</listitem>
- <listitem>MD5_80</listitem>
- <listitem>MD5_NOLIMIT</listitem>
- </itemizedlist></para>
- <para>Missing:</para>
- <para><itemizedlist>
- <listitem>SHA_XOR_40</listitem>
- </itemizedlist></para>
- </listitem>
- <listitem><para>B) Supported Ciphers:</para>
- <para><itemizedlist>
- <listitem>RC5_CBC_40</listitem>
- <listitem>RC5_CBC_56</listitem>
- <listitem>RC5_CBC</listitem>
- <listitem>DES_CBC</listitem>
- <listitem>DES_CBC_40</listitem>
- </itemizedlist></para>
- <para>Missing:</para>
- <para><itemizedlist>
- <listitem>NULL_bulk</listitem>
- <listitem>TRIPLE_DES_CBC_EDE</listitem>
- <listitem>IDEA_CBC_40</listitem>
- <listitem>IDEA_CBC_56</listitem>
- <listitem>IDEA_CBC</listitem>
- </itemizedlist></para>
- </listitem>
- <listitem><para>C) Supported Keys:</para>
- <para><itemizedlist>
- <listitem>RSA_anon</listitem>
- </itemizedlist></para>
- <para>Missing:</para>
- <para><itemizedlist>
- <listitem>RSA_anon_512</listitem>
- <listitem>RSA_anon_768</listitem>
- <listitem>RSA_NOLIMIT</listitem>
- <listitem>RSA_512</listitem>
- <listitem>RSA_768</listitem>
- <listitem>ECDH_anon</listitem>
- <listitem>ECDH_anon_113</listitem>
- <listitem>ECDH_anon_131</listitem>
- <listitem>ECDH_ECDSA_NOLIMIT</listitem>
- </itemizedlist></para>
+ <orderedlist numeration="upperalpha">
+ <listitem><para><itemizedlist title="Supported MACs:">
+ <listitem><para>SHA_0</para></listitem>
+ <listitem><para>SHA_40</para></listitem>
+ <listitem><para>SHA_80</para></listitem>
+ <listitem><para>SHA_NOLIMIT</para></listitem>
+ <listitem><para>MD5_40</para></listitem>
+ <listitem><para>MD5_80</para></listitem>
+ <listitem><para>MD5_NOLIMIT</para></listitem>
+ </itemizedlist>
+ <itemizedlist title="Missing">
+ <listitem><para>SHA_XOR_40</para></listitem>
+ </itemizedlist>
+ </para></listitem>
+ <listitem><itemizedlist title="Supported Ciphers:">
+ <listitem><para>RC5_CBC_40</para></listitem>
+ <listitem><para>RC5_CBC_56</para></listitem>
+ <listitem><para>RC5_CBC</para></listitem>
+ <listitem><para>DES_CBC</para></listitem>
+ <listitem><para>DES_CBC_40</para></listitem>
+ </itemizedlist>
+ <itemizedlist title="Missing">
+ <listitem><para>NULL_bulk</para></listitem>
+ <listitem><para>TRIPLE_DES_CBC_EDE</para></listitem>
+ <listitem><para>IDEA_CBC_40</para></listitem>
+ <listitem><para>IDEA_CBC_56</para></listitem>
+ <listitem><para>IDEA_CBC</para></listitem>
+ </itemizedlist>
+ </para></listitem>
+ <listitem><itemizedlist title="Supported Keys:">
+ <listitem><para>RSA_anon</para></listitem>
+ </itemizedlist>
+ <itemizedlist title="Missing">
+ <listitem><para>RSA_anon_512</para></listitem>
+ <listitem><para>RSA_anon_768</para></listitem>
+ <listitem><para>RSA_NOLIMIT</para></listitem>
+ <listitem><para>RSA_512</para></listitem>
+ <listitem><para>RSA_768</para></listitem>
+ <listitem><para>ECDH_anon</para></listitem>
+ <listitem><para>ECDH_anon_113</para></listitem>
+ <listitem><para>ECDH_anon_131</para></listitem>
+ <listitem><para>ECDH_ECDSA_NOLIMIT</para></listitem>
+ </itemizedlist>
<para>Keys might seem a shortcoming, but all mobiles support
RSA_anon. Some of the other RSA_anon keys (i.e. RSA_anon_512,
RSA_anon_768) are propably supported as well, just haven't been
tested yet.</para>
- </listitem>
- <listitem><para>D) All wtls states except:</para>
- <para><itemizedlist>
- <listitem>Suspend/Resume wtls session</listitem>
- <listitem>Cipher change when already connected. In practice
+ </para></listitem>
+ <listitem><para><itemizedlist title="All wtls states except:">
+ <listitem><para>Suspend/Resume wtls session</para></listitem>
+ <listitem><para>Cipher change when already connected. In practice
this is handled through another client hello, while
- already connected to the same client</listitem>
- </itemizedlist></para>
- </listitem>
- </itemizedlist></para>
+ already connected to the same client</para></listitem>
+ </itemizedlist>
+ </para></listitem>
+ </orderedlist></para>
-
-
- <para>The simplest working <literal>wtls</literal> group looks like this:
+ <para>The simplest working 'wtls' group looks like this:
<programlisting>
group = wtls
certificate-file = /etc/kannel/server.crt
@@ -2321,8 +2313,7 @@
</programlisting>
Can also be the same single combined pem file with both certificate and
- privatekey parts. The complete variable list for the <literal>wtls</literal> group is:
-</para>
+ privatekey parts. The complete variable list for the 'wtls' group is:
<sect1>
<title>Wtls configuration</title>
@@ -2360,6 +2351,9 @@
<entry valign="bottom">
Optional. Needed only if private key was created with a passphrase.
</entry></row>
+ </tbody>
+ </tgroup>
+ </table>
</sect1>
</chapter>
@@ -9096,13 +9090,12 @@
<sect1>
<title>Self-signed 1024-bit RSA SSL certificates using openssl</title>
<para>
- <itemizedlist>
- <listitem><para>1. Generate private key:</para>
- <para><literal>openssl genrsa -des3 -out server.key 1024</literal>
- </para>
+ <orderedlist numeration="arabic">
+ <listitem><para>Generate private key:</para>
+ <para><literal>openssl genrsa -des3 -out server.key 1024</literal></para>
<para>You will be asked for a passphrase.</para></listitem>
- <listitem><para>2. Generate a certificate request:</para>
+ <listitem><para>Generate a certificate request:</para>
<para><literal>
openssl req -new -key server.key -out server.csr
</literal></para>
@@ -9111,7 +9104,7 @@
generate the certificate for you, or you can sign it yourself.
</para></listitem>
- <listitem><para>3. Remove passphrase from key:</para>
+ <listitem><para>Remove passphrase from key:</para>
<para><literal>cp server.key server.key.org</literal>
</para>
<para><literal>openssl rsa -in server.key.org -out server.key
@@ -9119,7 +9112,7 @@
<para><literal>rm server.key.org</literal></para>
</listitem>
- <listitem><para>4. Self-sign the certificate:</para>
+ <listitem><para>Self-sign the certificate:</para>
<para>If you chose not to send the request to a Certificate
Authority, you will need to sign it yourself. This one is good
for 1 year:</para>
@@ -9127,7 +9120,7 @@
server.key -out server.crt</literal></para>
</listitem>
- <listitem><para>5. Move keys to desired location:</para>
+ <listitem><para>Move keys to desired location:</para>
<para><literal>mv server.crt /etc/kannel/public/server.crt</literal>
</para>
<para><literal>mv server.key /etc/kannel/private/server.key
@@ -9135,7 +9128,7 @@
<para><literal>mv server.csr /etc/ianwap/private/ianwap.csr (key
request)</literal></para>
</listitem>
- </itemizedlist>
+ </orderedlist>
</para>
<para>Update configuration accordingly</para>
</sect1>