chiark / gitweb /
ssh-ca
9 days agoetc/config.sh: Publish through dedicated server account. master
Mark Wooding [Tue, 24 Sep 2013 17:30:35 +0000]
etc/config.sh: Publish through dedicated server account.

It makes life better operationally.  Trust me.

9 days agoetc/hosts: Add jaguar.
Mark Wooding [Tue, 24 Sep 2013 17:30:22 +0000]
etc/hosts: Add jaguar.

7 months agoetc/config.sh, etc/hosts: Add satellite network.
Mark Wooding [Sat, 9 Feb 2013 17:38:42 +0000]
etc/config.sh, etc/hosts: Add satellite network.

7 months agobin/sign: Allow domain to be set in the hosts file.
Mark Wooding [Sat, 9 Feb 2013 17:37:50 +0000]
bin/sign: Allow domain to be set in the hosts file.

We extend our reach to other networks.

8 months agobin/sign: Include `known_hosts' entries in the signed bundle.
Mark Wooding [Tue, 29 Jan 2013 18:40:31 +0000]
bin/sign: Include `known_hosts' entries in the signed bundle.

Including the CA certificate.  Useful, since otherwise it's hard to
bootstrap.

8 months agobin/sign: Read fingerprint from master rather than publish directory.
Mark Wooding [Tue, 29 Jan 2013 18:39:36 +0000]
bin/sign: Read fingerprint from master rather than publish directory.

It's the authoritative source.

8 months agoetc/hosts: Add terror.
Mark Wooding [Tue, 29 Jan 2013 18:38:21 +0000]
etc/hosts: Add terror.

8 months agoetc/config.sh: Moving archive to stratocaster.
Mark Wooding [Mon, 14 Jan 2013 02:02:59 +0000]
etc/config.sh: Moving archive to stratocaster.

8 months agoetc/hosts: Add orange.
Mark Wooding [Sun, 13 Jan 2013 19:59:58 +0000]
etc/hosts: Add orange.

8 months agoetc/hosts: Publish `jazz.iodine' identity.
Mark Wooding [Sat, 5 Jan 2013 08:34:51 +0000]
etc/hosts: Publish `jazz.iodine' identity.

9 months agoetc/hosts: Now stratocaster is the Git server.
Mark Wooding [Sat, 29 Dec 2012 04:20:40 +0000]
etc/hosts: Now stratocaster is the Git server.

17 months agoInclude subnet-qualified names names for hosts.
Mark Wooding [Mon, 30 Apr 2012 08:59:14 +0000]
Include subnet-qualified names names for hosts.

17 months agoetc/hosts: Add nicknames for strat and tele.
Mark Wooding [Sun, 22 Apr 2012 10:23:16 +0000]
etc/hosts: Add nicknames for strat and tele.

17 months agoetc/hosts: Reformat entry for crybaby.
Mark Wooding [Sun, 22 Apr 2012 10:22:58 +0000]
etc/hosts: Reformat entry for crybaby.

17 months agoReturn of the virtual hosts.
Mark Wooding [Sat, 21 Apr 2012 22:58:45 +0000]
Return of the virtual hosts.

18 months agoetc/config.sh: Ooops. Fix the skew to one hour, not one day.
Mark Wooding [Mon, 19 Mar 2012 02:47:09 +0000]
etc/config.sh: Ooops.  Fix the skew to one hour, not one day.

18 months agobin/sign: Stupid typo fix: include leading `@' in CA entry file.
Mark Wooding [Mon, 12 Mar 2012 17:24:29 +0000]
bin/sign: Stupid typo fix: include leading `@' in CA entry file.

18 months agoetc/hosts: Actually commit this.
Mark Wooding [Mon, 12 Mar 2012 17:19:00 +0000]
etc/hosts: Actually commit this.

18 months agoconfig.sh: Increase scope for new address ranges.
Mark Wooding [Mon, 12 Mar 2012 17:18:02 +0000]
config.sh: Increase scope for new address ranges.

18 months agoetc/config.sh: Allow a little slack in the validity timing.
Mark Wooding [Mon, 12 Mar 2012 16:54:41 +0000]
etc/config.sh: Allow a little slack in the validity timing.

19 months agobin/sign: Remove spurious initial blank line.
Mark Wooding [Sun, 26 Feb 2012 22:18:59 +0000]
bin/sign: Remove spurious initial blank line.

19 months agobin/sign: Force use of v00 certificates.
Mark Wooding [Sat, 11 Feb 2012 15:39:44 +0000]
bin/sign: Force use of v00 certificates.

Debian stable doesn't understand v01.

2 years agobin/sign: More care with replacing the old publish directory.
Mark Wooding [Mon, 5 Sep 2011 09:17:55 +0000]
bin/sign: More care with replacing the old publish directory.

Don't delete the old backup or try to rename if there isn't a good newer
version.  It'll fail, and clobber the only good version we have.

2 years agoRearrange the filesystem structure.
Mark Wooding [Sun, 4 Sep 2011 18:46:44 +0000]
Rearrange the filesystem structure.

Remove the archive.  Remove the pointless extra directory level.  We're
going to use rsync instead of http.

2 years agoMajor change of approach and rewrite.
Mark Wooding [Sat, 13 Aug 2011 22:45:48 +0000]
Major change of approach and rewrite.

Fetching keys from the various hosts is silly: we must actually already
have them, otherwise SSH will complain.  Instead, assume that someone
has already arranged to collect the keys and put them in the host/
directory.  There's now a script to sign new certificates for them and
stash them in publish/.  There's another script to upload the publish/
directory to a webserver (or whatever).

2 years agoMinimal SSH certificate authority.
Mark Wooding [Sun, 10 Jul 2011 22:17:11 +0000]
Minimal SSH certificate authority.