Re: [tor-dev] Design for onionsite certification and use with Let's Encrypt

2015-08-26 Thread Jacob Appelbaum
On 8/26/15, Ben Laurie wrote: > On Mon, 24 Aug 2015 at 19:25 Paul Syverson > wrote: > >> If another browser it could be a setup config option whether clients >> can choose to be redirected via tor2web or simply always sent to a >> route-insecure address. I will assume for simplicity that all requ

Re: [tor-dev] Design for onionsite certification and use with Let's Encrypt

2015-08-26 Thread Ben Laurie
On Mon, 24 Aug 2015 at 19:25 Paul Syverson wrote: > If another browser it could be a setup config option whether clients > can choose to be redirected via tor2web or simply always sent to a > route-insecure address. I will assume for simplicity that all requests > for route-insecure addresses by

Re: [tor-dev] Design for onionsite certification and use with Let's Encrypt

2015-08-24 Thread Paul Syverson
On Mon, Aug 24, 2015 at 02:25:16PM -0400, Paul Syverson wrote: > If onion keys could be themselves linked in a PGP-like web of trust, Gah! Too many already used technical terms. By "onion key" I meant here private authentication key associated with the .onion address not private key for authentic

[tor-dev] Design for onionsite certification and use with Let's Encrypt

2015-08-24 Thread Paul Syverson
Hi Alec, Seth, Peter, Mike, all, I'm enthused about the progress Alec reported about the Onion RFC for certs for onion addresses in recent tor-dev posts and elsewhere. I wanted to further discuss a design for binding .onion addresses with registered (route-insecure) addresses. This ties in to in-