chiark / gitweb /
ssh-ca
3 weeks agoetc/config.sh, etc/hosts: Add satellite network. master
Mark Wooding [Sat, 9 Feb 2013 17:38:42 +0000]
etc/config.sh, etc/hosts: Add satellite network.

3 weeks agobin/sign: Allow domain to be set in the hosts file.
Mark Wooding [Sat, 9 Feb 2013 17:37:50 +0000]
bin/sign: Allow domain to be set in the hosts file.

We extend our reach to other networks.

4 weeks agobin/sign: Include `known_hosts' entries in the signed bundle.
Mark Wooding [Tue, 29 Jan 2013 18:40:31 +0000]
bin/sign: Include `known_hosts' entries in the signed bundle.

Including the CA certificate.  Useful, since otherwise it's hard to
bootstrap.

4 weeks agobin/sign: Read fingerprint from master rather than publish directory.
Mark Wooding [Tue, 29 Jan 2013 18:39:36 +0000]
bin/sign: Read fingerprint from master rather than publish directory.

It's the authoritative source.

4 weeks agoetc/hosts: Add terror.
Mark Wooding [Tue, 29 Jan 2013 18:38:21 +0000]
etc/hosts: Add terror.

6 weeks agoetc/config.sh: Moving archive to stratocaster.
Mark Wooding [Mon, 14 Jan 2013 02:02:59 +0000]
etc/config.sh: Moving archive to stratocaster.

7 weeks agoetc/hosts: Add orange.
Mark Wooding [Sun, 13 Jan 2013 19:59:58 +0000]
etc/hosts: Add orange.

8 weeks agoetc/hosts: Publish `jazz.iodine' identity.
Mark Wooding [Sat, 5 Jan 2013 08:34:51 +0000]
etc/hosts: Publish `jazz.iodine' identity.

2 months agoetc/hosts: Now stratocaster is the Git server.
Mark Wooding [Sat, 29 Dec 2012 04:20:40 +0000]
etc/hosts: Now stratocaster is the Git server.

10 months agoInclude subnet-qualified names names for hosts.
Mark Wooding [Mon, 30 Apr 2012 08:59:14 +0000]
Include subnet-qualified names names for hosts.

10 months agoetc/hosts: Add nicknames for strat and tele.
Mark Wooding [Sun, 22 Apr 2012 10:23:16 +0000]
etc/hosts: Add nicknames for strat and tele.

10 months agoetc/hosts: Reformat entry for crybaby.
Mark Wooding [Sun, 22 Apr 2012 10:22:58 +0000]
etc/hosts: Reformat entry for crybaby.

10 months agoReturn of the virtual hosts.
Mark Wooding [Sat, 21 Apr 2012 22:58:45 +0000]
Return of the virtual hosts.

11 months agoetc/config.sh: Ooops. Fix the skew to one hour, not one day.
Mark Wooding [Mon, 19 Mar 2012 02:47:09 +0000]
etc/config.sh: Ooops.  Fix the skew to one hour, not one day.

11 months agobin/sign: Stupid typo fix: include leading `@' in CA entry file.
Mark Wooding [Mon, 12 Mar 2012 17:24:29 +0000]
bin/sign: Stupid typo fix: include leading `@' in CA entry file.

11 months agoetc/hosts: Actually commit this.
Mark Wooding [Mon, 12 Mar 2012 17:19:00 +0000]
etc/hosts: Actually commit this.

11 months agoconfig.sh: Increase scope for new address ranges.
Mark Wooding [Mon, 12 Mar 2012 17:18:02 +0000]
config.sh: Increase scope for new address ranges.

11 months agoetc/config.sh: Allow a little slack in the validity timing.
Mark Wooding [Mon, 12 Mar 2012 16:54:41 +0000]
etc/config.sh: Allow a little slack in the validity timing.

12 months agobin/sign: Remove spurious initial blank line.
Mark Wooding [Sun, 26 Feb 2012 22:18:59 +0000]
bin/sign: Remove spurious initial blank line.

12 months agobin/sign: Force use of v00 certificates.
Mark Wooding [Sat, 11 Feb 2012 15:39:44 +0000]
bin/sign: Force use of v00 certificates.

Debian stable doesn't understand v01.

17 months agobin/sign: More care with replacing the old publish directory.
Mark Wooding [Mon, 5 Sep 2011 09:17:55 +0000]
bin/sign: More care with replacing the old publish directory.

Don't delete the old backup or try to rename if there isn't a good newer
version.  It'll fail, and clobber the only good version we have.

17 months agoRearrange the filesystem structure.
Mark Wooding [Sun, 4 Sep 2011 18:46:44 +0000]
Rearrange the filesystem structure.

Remove the archive.  Remove the pointless extra directory level.  We're
going to use rsync instead of http.

18 months agoMajor change of approach and rewrite.
Mark Wooding [Sat, 13 Aug 2011 22:45:48 +0000]
Major change of approach and rewrite.

Fetching keys from the various hosts is silly: we must actually already
have them, otherwise SSH will complain.  Instead, assume that someone
has already arranged to collect the keys and put them in the host/
directory.  There's now a script to sign new certificates for them and
stash them in publish/.  There's another script to upload the publish/
directory to a webserver (or whatever).

19 months agoMinimal SSH certificate authority.
Mark Wooding [Sun, 10 Jul 2011 22:17:11 +0000]
Minimal SSH certificate authority.