[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-relays] Questions about OfflineMasterKey



> Which one are the RSA keys and which one the ED25519 ones? 

Ed25519 master:
ed25519_master_id_public_key
ed25519_master_id_secret_key
Ed25519 signing:
ed25519_signing_cert
ed25519_signing_secret_key

RSA:
secret_id_key

>>> * To run the node with `OfflineMasterKey 1` you need to copy all the
>>> files generated in the previous step *with the exception of the master key*.
>>
>> more precisely: a relay in "OfflineMasterKey 1" mode requires 3 files:
>> (this is the absolute minimum):
>>
>> ed25519_signing_cert
>> ed25519_signing_secret_key
> 
> Here you list only 2 files, which one is the third?

since I'm copying also the RSA key I initially wrote "3" but since it is
not required I removed it (it gets generated if there is none)


>> Reminder: When you play around with this feature: always make sure to
>> keep your Ed25519 + RSA keys. If your Ed25519 key changes while the RSA
>> key remains, your relay will be rejected since these keys are pinned
>> (for security).
> 
> I should keep the files:
> ```
> secret_id_key
> secret_onion_key
> secret_onion_key_ntor
> secret_onion_key_ntor.old
> secret_onion_key.old
> ```
> should be kept of the relay, do they matter?

keep the /keys subfolder of your datadir and you are fine (you don't
need them all but it does not hurt)


-- 
https://mastodon.social/@nusenu
https://twitter.com/nusenu_

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays