[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-relays] published descriptor missing from consensus




Scott Bennett:
> In the meantime, I had read some recent postings
> to this list and had noted some remarks regarding mismatched RSA and ED25519
> keys,
Since I was one of the persons mentioning key pinning on this list
I'd like to clarify my previous info [1] about the key pinning enforced
by dir auths.

[1] https://lists.torproject.org/pipermail/tor-relays/2017-May/012390.html :
> Reminder: When you play around with this feature: always make sure to
> keep your Ed25519 + RSA keys. If your Ed25519 key changes while the RSA
> key remains, your relay will be rejected since these keys are pinned
> (for security).

This safeguard has been introduced in tor 0.3.0.x and will only be in
effect once enough tor directory authorities run a version with that
feature and the setting at its default value, which is currently not yet
the case so the problem you are having is unlikely related to key pinning.
https://consensus-health.torproject.org/#authorityversions



-- 
https://mastodon.social/@nusenu
https://twitter.com/nusenu_

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays