summaryrefslogtreecommitdiff
path: root/doc/dev
Commit message (Collapse)AuthorAgeFilesLines
* tor-hsservice: Rewrite maybe_generate_hsid using KeyMgr::generate.Gabriela Moldovan2024-02-011-1/+0
| | | | | | | | | | | | | | | We will soon remove the `KeyMgr::*_with_derived()` functions, so we need to rewrite `maybe_generate_hsid` using `KeyMgr::get` and `KeyMgr::generate`. An important point to note is that `maybe_generate_hsid` no longer stores the `KP_hs_id` in the key store. The reason we originally put the `KP_hs_id` in the keystore in the first place was to support offline HsId mode. However, offline HsId mode was never fully implemented (#1194), and the decision to put the public part of the HsId in the keystore is controversial (#1195). We can revisit this decision when we implement #1194, but for now, we don't need a separate `KP_hs_Id` entry in the keystore.
* tor-hsservice: Rename the service keystore dir to "hss".Gabriela Moldovan2024-02-011-5/+5
| | | | | | | | | | | The onion service keys now live in the `hss/<nickname>` subdirectory within the keystore. This layout change is **not** backwards-compatible, so if you want to use your existing hidden service keys, you will need to manually move them to `<keystore_root>/hss`. Closes #1260
* tor-keymgr: Strip .onion suffix from HsId before building Slug.Gabriela Moldovan2024-01-311-2/+2
| | | | | | We are about to replace `ArtiPathComponent` with `Slug`, but `Slug`s don't support `.`, so let's strip the `.onion` suffix before encoding it in the `ArtiPath`.
* Update sponsor 101 numbers.Alexander Færøy2024-01-231-0/+26
|
* Merge branch 'typos' into 'main'Ian Jackson2024-01-091-3/+3
|\ | | | | | | | | Fix typos See merge request tpo/core/arti!1852
| * Fix typosDimitris Apostolou2024-01-081-3/+3
| |
* | dev doc: Mention which keymgr APIs the CLI will be using.Gabriela Moldovan2024-01-081-7/+114
| |
* | dev doc: Add a TODO about `arti hss auth-clients`.Gabriela Moldovan2024-01-081-1/+2
| |
* | doc dev: Add a TODO about --pub-format=artiGabriela Moldovan2024-01-081-0/+3
| |
* | Revert "dev doc: Add import-key/export-key hsc subcommands."Gabriela Moldovan2024-01-081-96/+0
| | | | | | | | This reverts commit 2c4e3773baf18b0f40e0d96c56d72c5515691a63.
* | dev doc: Add TODO about converting C Tor state to Arti state.Gabriela Moldovan2024-01-081-0/+4
| |
* | dev doc: Clarify how new-service is supposed to work.Gabriela Moldovan2024-01-081-0/+11
| |
* | dev doc: Auth public keys should be printed to stdout (fmt).Gabriela Moldovan2024-01-081-6/+5
| |
* | dev doc: Auth public keys should be printed to stdout.Gabriela Moldovan2024-01-081-14/+14
| |
* | Add a note about destroy-and-recreate.Gabriela Moldovan2024-01-081-0/+27
| |
* | dev doc: Clarify how generate-online-keys is supposed to work.Gabriela Moldovan2024-01-081-16/+25
| |
* | dev doc: Make --up-to specify a timestamp/duration.Gabriela Moldovan2024-01-081-7/+13
| |
* | dev doc: Generalize the keys-verify description.Gabriela Moldovan2024-01-081-1/+1
| | | | | | | | This command is not specific to services.
* | doc dev: Rename destroy-service to destroy.Gabriela Moldovan2024-01-081-6/+6
| |
* | dev doc: Add import-key/export-key hsc subcommands.Gabriela Moldovan2024-01-081-0/+96
| |
* | dev doc: Add TODO about managing the authorized clients.Gabriela Moldovan2024-01-081-0/+22
| |
* | dev doc: s/new-identity/new-service and clarify its meaning.Gabriela Moldovan2024-01-081-14/+22
| |
* | dev doc: Explain what generate-online-keys is used for.Gabriela Moldovan2024-01-081-8/+13
| |
* | dev doc: s/generate-all/generate-online-keysGabriela Moldovan2024-01-081-11/+11
| |
* | dev doc: Move the plumbing subcommands under the keys-raw subcommand.Gabriela Moldovan2024-01-081-39/+77
| |
* | dev doc: Rename the subcommand for erasing service state.Gabriela Moldovan2024-01-081-6/+6
| |
* | dev doc: Add keymgr CLI doc sketch.Gabriela Moldovan2024-01-081-0/+856
|/ | | | | | | | | | This is the second draft of the keymgr CLI design. I've omitted a lot of details which I think ought to be included in the final CLI docs. This document lists the most important functionality we're going to need from this CLI.
* hssvc-ipt-algorithms.md: Minor updatesIan Jackson2023-11-291-10/+8
|
* hssvc-ipt-algorithms.md: Talk about ipt_set, which is nontrivial nowIan Jackson2023-11-291-7/+11
|
* hssvc-ipt-algorithms.md: Move some text to ipt_setIan Jackson2023-11-291-67/+0
| | | | | This is describing the detailed algorithm in compute_iptsetstatus_publish. Move it there (and add an xref).
* hssvc-ipt-algorithms.md: Move some text to ipt_mgrIan Jackson2023-11-291-32/+0
| | | | | This is describing the detailed algorithm in idempotently_progress_things_now. Move it there (and add an xref).
* hssvc-ipt-algorithms.md: Delete rendundant textIan Jackson2023-11-291-49/+0
| | | | | | | | This is describing our data structures and IPT states. But we have this documented elsewhere, largely. There are a few sentences here that can usefully be replaced with a bit of extra text in the data structure docs.
* dev doc: Update keymgr paths to mention the new denotator separator.Gabriela Moldovan2023-11-021-3/+3
|
* Fix date typo from Gabigabi-2502023-10-241-2/+2
|
* Update sponsor 101 numbers.Alexander Færøy2023-10-241-0/+26
|
* dev-doc: Document the service keys currently supported by keymgr.Gabriela Moldovan2023-10-131-4/+9
|
* tor-keymgr: Encode whether the key is public or private in the file extension.Gabriela Moldovan2023-10-131-2/+2
| | | | | | | | | | | | | | There are 2 reasons to make this change: * because having the word `private` in the extension will make it more difficult to accidentally misuse or misplace a private key (see https://gitlab.torproject.org/tpo/core/arti/-/merge_requests/1618#note_2947461) * because `Keystore`s will soon grow a `list()` function returning all `(ArtiPath, KeyType)`s in the keystore, and in order for `ArtiNativeKeystore` to implement this function, it will need to be able to reverse the `KeyType -> file extension` mapping (if two different `KeyType`s are mapped to the same extension, `ArtiNativeKeystore`s won't be able to reverse the mapping)
* Update changed_crates and Release.md to robustify release processNick Mathewson2023-10-041-0/+7
| | | | | | | | | | In particular, this change should help avoid the kind of problem we ran into as #1054 and fixed with 00e4405943498754, where a crate changed only in which versions of our crates it depended upon, and we didn't notice that we had to update its version too. This commit also fixes a couple of minor issues in the `changed_crates` script, and gives it a verbose mode.
* dev docs: Document the `ArtiPath`s recognized by the key manager.Gabriela Moldovan2023-09-141-0/+15
|
* hssvc-high-level-apis: link to MR comments; add num_intro_pointsNick Mathewson2023-08-281-0/+7
|
* hss-apis: Draft for authorization.Nick Mathewson2023-08-251-0/+20
|
* hssvc api draft: add a switch for single onion services.Nick Mathewson2023-08-251-0/+5
|
* Draft high-level APIs for onion servicesNick Mathewson2023-08-251-0/+247
|
* Use "typos-cli" to fix a bunch of typos.Nick Mathewson2023-08-222-3/+3
|
* Merge branch 'key-uses' into 'main'Ian Jackson2023-08-091-0/+144
|\ | | | | | | | | key-management.md: Use scenarios See merge request tpo/core/arti!1445
| * key-management.md: Fix typosgabi-2502023-08-081-3/+3
| |
| * key-management.md: Use scenariosIan Jackson2023-07-281-0/+143
| |
| * key-management.md: Fix pandoc formattingIan Jackson2023-07-281-0/+1
| | | | | | | | Add a missing blank line.
* | Merge branch 'ipts2bis' into 'main'Ian Jackson2023-08-011-16/+42
|\ \ | | | | | | | | | | | | dev notes: Draft IPT algorithm: Overhaul for latest version of torspec!154 See merge request tpo/core/arti!1444
| * | dev notes: Draft IPT algorithm: Make IPT persistence optionalIan Jackson2023-07-281-2/+11
| | | | | | | | | | | | As per current version of torpsec!154