| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate. | Gabriela Moldovan | 2024-02-01 | 1 | -1/+0 |
| | | | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore. | ||||
| * | tor-hsservice: Rename the service keystore dir to "hss". | Gabriela Moldovan | 2024-02-01 | 1 | -5/+5 |
| | | | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260 | ||||
| * | tor-keymgr: Strip .onion suffix from HsId before building Slug. | Gabriela Moldovan | 2024-01-31 | 1 | -2/+2 |
| | | | | | | | We are about to replace `ArtiPathComponent` with `Slug`, but `Slug`s don't support `.`, so let's strip the `.onion` suffix before encoding it in the `ArtiPath`. | ||||
| * | Merge branch 'typos' into 'main' | Ian Jackson | 2024-01-09 | 1 | -3/+3 |
| |\ | | | | | | | | | Fix typos See merge request tpo/core/arti!1852 | ||||
| | * | Fix typos | Dimitris Apostolou | 2024-01-08 | 1 | -3/+3 |
| | | | |||||
| * | | dev doc: Mention which keymgr APIs the CLI will be using. | Gabriela Moldovan | 2024-01-08 | 1 | -7/+114 |
| | | | |||||
| * | | dev doc: Add a TODO about `arti hss auth-clients`. | Gabriela Moldovan | 2024-01-08 | 1 | -1/+2 |
| | | | |||||
| * | | doc dev: Add a TODO about --pub-format=arti | Gabriela Moldovan | 2024-01-08 | 1 | -0/+3 |
| | | | |||||
| * | | Revert "dev doc: Add import-key/export-key hsc subcommands." | Gabriela Moldovan | 2024-01-08 | 1 | -96/+0 |
| | | | | | | | | | This reverts commit 2c4e3773baf18b0f40e0d96c56d72c5515691a63. | ||||
| * | | dev doc: Add TODO about converting C Tor state to Arti state. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+4 |
| | | | |||||
| * | | dev doc: Clarify how new-service is supposed to work. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+11 |
| | | | |||||
| * | | dev doc: Auth public keys should be printed to stdout (fmt). | Gabriela Moldovan | 2024-01-08 | 1 | -6/+5 |
| | | | |||||
| * | | dev doc: Auth public keys should be printed to stdout. | Gabriela Moldovan | 2024-01-08 | 1 | -14/+14 |
| | | | |||||
| * | | Add a note about destroy-and-recreate. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+27 |
| | | | |||||
| * | | dev doc: Clarify how generate-online-keys is supposed to work. | Gabriela Moldovan | 2024-01-08 | 1 | -16/+25 |
| | | | |||||
| * | | dev doc: Make --up-to specify a timestamp/duration. | Gabriela Moldovan | 2024-01-08 | 1 | -7/+13 |
| | | | |||||
| * | | dev doc: Generalize the keys-verify description. | Gabriela Moldovan | 2024-01-08 | 1 | -1/+1 |
| | | | | | | | | | This command is not specific to services. | ||||
| * | | doc dev: Rename destroy-service to destroy. | Gabriela Moldovan | 2024-01-08 | 1 | -6/+6 |
| | | | |||||
| * | | dev doc: Add import-key/export-key hsc subcommands. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+96 |
| | | | |||||
| * | | dev doc: Add TODO about managing the authorized clients. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+22 |
| | | | |||||
| * | | dev doc: s/new-identity/new-service and clarify its meaning. | Gabriela Moldovan | 2024-01-08 | 1 | -14/+22 |
| | | | |||||
| * | | dev doc: Explain what generate-online-keys is used for. | Gabriela Moldovan | 2024-01-08 | 1 | -8/+13 |
| | | | |||||
| * | | dev doc: s/generate-all/generate-online-keys | Gabriela Moldovan | 2024-01-08 | 1 | -11/+11 |
| | | | |||||
| * | | dev doc: Move the plumbing subcommands under the keys-raw subcommand. | Gabriela Moldovan | 2024-01-08 | 1 | -39/+77 |
| | | | |||||
| * | | dev doc: Rename the subcommand for erasing service state. | Gabriela Moldovan | 2024-01-08 | 1 | -6/+6 |
| | | | |||||
| * | | dev doc: Add keymgr CLI doc sketch. | Gabriela Moldovan | 2024-01-08 | 1 | -0/+856 |
| |/ | | | | | | | | | | This is the second draft of the keymgr CLI design. I've omitted a lot of details which I think ought to be included in the final CLI docs. This document lists the most important functionality we're going to need from this CLI. | ||||
| * | hssvc-ipt-algorithms.md: Minor updates | Ian Jackson | 2023-11-29 | 1 | -10/+8 |
| | | |||||
| * | hssvc-ipt-algorithms.md: Talk about ipt_set, which is nontrivial now | Ian Jackson | 2023-11-29 | 1 | -7/+11 |
| | | |||||
| * | hssvc-ipt-algorithms.md: Move some text to ipt_set | Ian Jackson | 2023-11-29 | 1 | -67/+0 |
| | | | | | | This is describing the detailed algorithm in compute_iptsetstatus_publish. Move it there (and add an xref). | ||||
| * | hssvc-ipt-algorithms.md: Move some text to ipt_mgr | Ian Jackson | 2023-11-29 | 1 | -32/+0 |
| | | | | | | This is describing the detailed algorithm in idempotently_progress_things_now. Move it there (and add an xref). | ||||
| * | hssvc-ipt-algorithms.md: Delete rendundant text | Ian Jackson | 2023-11-29 | 1 | -49/+0 |
| | | | | | | | | | This is describing our data structures and IPT states. But we have this documented elsewhere, largely. There are a few sentences here that can usefully be replaced with a bit of extra text in the data structure docs. | ||||
| * | dev doc: Update keymgr paths to mention the new denotator separator. | Gabriela Moldovan | 2023-11-02 | 1 | -3/+3 |
| | | |||||
| * | dev-doc: Document the service keys currently supported by keymgr. | Gabriela Moldovan | 2023-10-13 | 1 | -4/+9 |
| | | |||||
| * | tor-keymgr: Encode whether the key is public or private in the file extension. | Gabriela Moldovan | 2023-10-13 | 1 | -2/+2 |
| | | | | | | | | | | | | | | | There are 2 reasons to make this change: * because having the word `private` in the extension will make it more difficult to accidentally misuse or misplace a private key (see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1618#note_2947461) * because `Keystore`s will soon grow a `list()` function returning all `(ArtiPath, KeyType)`s in the keystore, and in order for `ArtiNativeKeystore` to implement this function, it will need to be able to reverse the `KeyType -> file extension` mapping (if two different `KeyType`s are mapped to the same extension, `ArtiNativeKeystore`s won't be able to reverse the mapping) | ||||
| * | dev docs: Document the `ArtiPath`s recognized by the key manager. | Gabriela Moldovan | 2023-09-14 | 1 | -0/+15 |
| | | |||||
| * | hssvc-high-level-apis: link to MR comments; add num_intro_points | Nick Mathewson | 2023-08-28 | 1 | -0/+7 |
| | | |||||
| * | hss-apis: Draft for authorization. | Nick Mathewson | 2023-08-25 | 1 | -0/+20 |
| | | |||||
| * | hssvc api draft: add a switch for single onion services. | Nick Mathewson | 2023-08-25 | 1 | -0/+5 |
| | | |||||
| * | Draft high-level APIs for onion services | Nick Mathewson | 2023-08-25 | 1 | -0/+247 |
| | | |||||
| * | Use "typos-cli" to fix a bunch of typos. | Nick Mathewson | 2023-08-22 | 1 | -2/+2 |
| | | |||||
| * | Merge branch 'key-uses' into 'main' | Ian Jackson | 2023-08-09 | 1 | -0/+144 |
| |\ | | | | | | | | | key-management.md: Use scenarios See merge request tpo/core/arti!1445 | ||||
| | * | key-management.md: Fix typos | gabi-250 | 2023-08-08 | 1 | -3/+3 |
| | | | |||||
| | * | key-management.md: Use scenarios | Ian Jackson | 2023-07-28 | 1 | -0/+143 |
| | | | |||||
| | * | key-management.md: Fix pandoc formatting | Ian Jackson | 2023-07-28 | 1 | -0/+1 |
| | | | | | | | | | Add a missing blank line. | ||||
| * | | dev notes: Draft IPT algorithm: Make IPT persistence optional | Ian Jackson | 2023-07-28 | 1 | -2/+11 |
| | | | | | | | | | As per current version of torpsec!154 | ||||
| * | | dev notes: Draft IPT algorithm: Reuse relays when cycling IPT | Ian Jackson | 2023-07-28 | 1 | -10/+22 |
| | | | |||||
| * | | dev notes: Draft IPT algorithm: Maintain k*N, not 2N | Ian Jackson | 2023-07-28 | 1 | -3/+7 |
| | | | | | | | | | Make this a separate parameter. | ||||
| * | | dev notes: Draft IPT algorithm: Minor clarifications | Ian Jackson | 2023-07-26 | 1 | -3/+4 |
| |/ | |||||
| * | dev notes: Draft IPT algorithm: Added TODO re previous descriptor semantics | Ian Jackson | 2023-07-26 | 1 | -0/+5 |
| | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1429#note_2924491 | ||||
| * | dev notes: Draft IPT algorithm: Added TODO/xref re tuning | Ian Jackson | 2023-07-26 | 1 | -0/+4 |
| | | | | | | Prompted by https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1429#note_2924530 | ||||
