>
If someone gets the client cert and key, they can probably fake the request to get the decryption password.Yes, that is a weakness, which is openly addressed in the FAQ: https://www.recompile.se/mandos/man/intro.8mandos#quick TLDR: It only works if an attacker is pretty quick about it. See also here: https://www.recompile.se/mandos/man/intro.8mandos#security
> And what about the vector where someone attacks the CA that issued the certs?
There is no CA involved, nor any X.509 keys. The keys used in TLS are ed25519 raw keys, and the server has a list of, and checks, individual key fingerprints.
> This may be moot if you are using self-signed certs, but of course those introduce their own management issues.
Yes, you have to generate and transport keys out-of-band (i.e. by hand) as part of the initial setup. The instructions on exactly how to do this are shown as part of installation and configuration.
> a pretty gnarly fail-closed kill switch
That’s a feature. A security system should fail closed.
> Presumably there’s a mechanism that allows a self-destructed pair or cluster of these [mandos]’d servers to go back to a normal operating mode?
Yes. You either type in a password on the console on one of the servers, or use a dropbear to ssh in remotely to do it.
> A section called “reasons you may not want to use this” that is very up front about those seems appropriate.
The project is mostly intended for those people who have already decided that full-disk encryption is a requirement, and Mandos is meant to alleviate some of the pain which they have already accepted. But sure, I see your point.