Re: [Sks-devel] Pools & HSTS header

2016-05-25 Thread Christian Felsing
Am 26.05.2016 um 00:47 schrieb Valentin Sundermann: I enforce HTTPS on all my domains by sending the HSTS header to my visitors. HSTS forces the browser to use in future only secure same here, excluding that I am using hardened flavour by adding my domain to "HSTS preload" at several browsers,

Re: [Sks-devel] Pools & HSTS header

2016-05-25 Thread Daniel Roesler
I wrote up how I have nginx configured to do HSTS while being in the pool. https://daylightpirates.org/index.html?posts/2016-05-25_hsts-hkps.md Daniel On Wed, May 25, 2016 at 3:47 PM, Valentin Sundermann wrote: > Hi, > > I enforce HTTPS on all my domains by sending the HSTS header to my > visit

[Sks-devel] Pools & HSTS header

2016-05-25 Thread Valentin Sundermann
Hi, I enforce HTTPS on all my domains by sending the HSTS header to my visitors. HSTS forces the browser to use in future only secure connections to this domain. More info on Wikipedia[1] :) Since my keyserver could be added to pools of keyservers without any notice to me. It could be possible tha

Re: [Sks-devel] Oh, Jeeez...!

2016-05-25 Thread Robert J. Hansen
> Let client solve a simple integer factorization of a random number given > by server with e.g. 64bit build from two prime numbers. Please sanity-check your ideas first. Trial division on a 64-bit number requires trying each prime up to 2**32. There are about 200 million of them. 200 million *

[Sks-devel] seeking peers for keyserver.flippylosaurus.eu

2016-05-25 Thread Hillebrand van de Groep
Hey there - I'd like to request peering. I'm running a SKS server version 1.1.5 - hostname keyserver.flippylosaurus.eu. It should be accessible via IPv4 (v6 should work in theory, haven't been able to test it so let me know if it's broken). The server is located in Amsterdam (NL) with a symmetric

Re: [Sks-devel] Oh, Jeeez...!

2016-05-25 Thread Christian Felsing
Am 25.05.2016 um 18:13 schrieb Valentin Sundermann: Hi, Can we add a proof of work mechanism to make adding a key to the server more "costly" ?. Let client solve a simple integer factorization of a random number given by server with e.g. 64bit build from two prime numbers. Client has to fin

Re: [Sks-devel] Oh, Jeeez...!

2016-05-25 Thread Valentin Sundermann
Hi, > Can we add a proof of work mechanism to make adding a key to the server > more "costly" ?. There are some blockchain based approaches on how to distribute keys (or managing identity) like Blockstack(.org) with their "blockchain id". Their current model is, that you order a normal name (like d