sks-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Sks-devel] Tor hidden service /onionbalance for hkp


From: Kristian Fiskerstrand
Subject: Re: [Sks-devel] Tor hidden service /onionbalance for hkp
Date: Fri, 13 Nov 2015 15:45:04 +0100
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 11/13/2015 03:42 PM, Daniel Kahn Gillmor wrote:
> On Fri 2015-11-13 06:08:37 -0500, Kristian Fiskerstrand wrote:
>> On 11/13/2015 11:27 AM, Christoph Egger wrote:
>>> Is there some documentation published on what is needed on the
>>> side of a keyserver operator? I'd really like to get my
>>> keyserver added there (next week sounds good for doing the
>>> work) but don't really know what is needed.
>> 
>> 1) set up a tor hidden service for 11371 (it is encrypted to the 
>> endpoint, so no TLS needed to add complexity), see [0]
> 
> Please make sure that the tor hidden service is pointing at your
> http reverse proxy, and not at your sks listener directly.

Fair enough to make this explicit, wasn't really in the front of my
mind that someone might send it to the direct instance  when writing
up that list :)

> 
>> 2) Verify that it is stable for some time 3) send OpenPGP signed
>> onion address to me
> 
> Kristian, i hope that when requests come in for tor hidden
> services, you are verifying that the hidden service itself meets
> the same requirements needed for the "RProx" column (at
> https://sks-keyservers.net/status/) before including them in the
> onionbalance pool.

its not automated, so not the same dynamic nature, but yeah I look at
a few things when adding it initially..

- -- 
- ----------------------------
Kristian Fiskerstrand
Blog: http://blog.sumptuouscapital.com
Twitter: @krifisk
- ----------------------------
Public OpenPGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
- ----------------------------
Ne nuntium necare
Don't kill the messenger
-----BEGIN PGP SIGNATURE-----

iQEcBAEBCgAGBQJWRfdrAAoJECULev7WN52FPEkH/id+S/wUWdLqxGEOfpGSXsSg
gn6Sk4EX9aV3MZCdgEm/txBVIBtGtd/YfaYcNoxcfTIG1w5DbVlKKdv2y+cD+LLe
Wxv2HKvD8luMxpeSnTDQza8w1Yw2JcvWHztpUoBm+r++oAW4l8G9pInLSefKF4eh
+XjBgCkty1z/uOdS4Ikh8UPcD6duQjKP5PJsVYQmnmBS4mGjI7WXCJBySQ4xXF7R
XGwfRXG2XETYcAQu0PywLWHv3bCz63zRIQkUy9eu3I7oaKISNrWJLlAtUxz3b/R4
SVMsee50BrgUg5taK/xDjTSgxQcaQCYTAJ7ZoFR+usd/vMAhMMZ232tuE7FWsBM=
=v6/a
-----END PGP SIGNATURE-----



reply via email to

[Prev in Thread] Current Thread [Next in Thread]