X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~mdw/git/zones/blobdiff_plain/77fbb917c3fe80bd00a210cbc05769d5c1a0cbb7..668d8477199b901515e9de79341568b13cdb4521:/distorted.lisp?ds=sidebyside diff --git a/distorted.lisp b/distorted.lisp index 54d5dd8..22f6726 100644 --- a/distorted.lisp +++ b/distorted.lisp @@ -150,25 +150,33 @@ (defzone distorted.org.uk :public-key :sha-256 #p"https-jazz"))) ((bugs lists db ftp) (colo :svc telecaster.colo :sshfp "telecaster") (jump :svc telecaster.jump :sshfp "telecaster")) - ((bugs lists ftp) :tlsa (:https (:service-certificate-constraint - :public-key :sha-256 - #p"https-telecaster"))) + ((bugs lists ftp) :tlsa (:https #3=(:service-certificate-constraint + :public-key :sha-256 + #p"https-telecaster"))) (dyndns :svc telecaster.jump :sshfp "telecaster") ((git www mail) (colo :svc stratocaster.colo :sshfp "stratocaster") (jump :svc stratocaster.jump :sshfp "stratocaster")) - ((www git mail @) :tlsa (:https (:service-certificate-constraint - :public-key :sha-256 - #p"https-stratocaster"))) + ((www git mail @) :tlsa (:https #2=(:service-certificate-constraint + :public-key :sha-256 + #p"https-stratocaster"))) (www-cache :tlsa (3127 #1=(:trust-anchor-assertion :certificate :sha-256 #p"distorted-ca"))) - ((bugs lists) :tlsa (:smtp #1#)) - (mail :tlsa ((:smtp :submission :imap :imaps) #1#)) + (mail :tlsa ((:submission :imap :imaps) #1# #3#)) + (mail :tlsa (:smtp #1# + (:domain-issued-certificate + :public-key :sha-256 #p"smtps-stratocaster"))) + ((bugs lists) :tlsa (:smtp #1# + (:domain-issued-certificate + :public-key :sha-256 #p"smtps-telecaster"))) :svc #+view/inside stratocaster.colo #-view/inside stratocaster.jump (cabal :svc stratocaster.colo :sshfp "stratocaster") ;; Local services. (rawk (unsafe :svc artist.unsafe) (dmz :svc artist.dmz)) + (rawk :tlsa (:https (:service-certificate-constraint + :public-key :sha-256 + #p"https-artist"))) (mirror (dmz :svc roadstar.dmz :sshfp "roadstar") (unsafe :svc roadstar.unsafe :sshfp "roadstar"))