[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #4549 [Tor Bridge]: Implement user-defined certificate strings through torrc (part of the proposal 179 efforts)
#4549: Implement user-defined certificate strings through torrc (part of the
proposal 179 efforts)
------------------------+---------------------------------------------------
Reporter: asn | Owner:
Type: defect | Status: needs_review
Priority: normal | Milestone: Tor: 0.2.3.x-final
Component: Tor Bridge | Version:
Keywords: | Parent: #3972
Points: | Actualpoints:
------------------------+---------------------------------------------------
Comment(by asn):
Replying to [comment:9 nickm]:
> So here's what I'd suggest:
>
> Let the user configure an issuerDN "I" and a subjectDN "S".
>
> When there's just one cert presented in plaintext, it should probably
look self-signed. So it should have issuerDN=subjectDN=S. When there are
two certificates, the link cert should have issuerDN=I and subjectDN=S,
and the identity cert needs issuerDN=subjectDN=I.
>
> Does that work out?
I think it's doable. It will require us to define two extra certificates.
One 'self-signed presented-in-cleartext' certificate to be used in v2/v3,
and one 'signed-by-the-identity-certificate presented-in-cleartext'
certificate to be used in v1.
I'll try to do it today.
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/4549#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs