소스 검색

add a note about tor vs. tls

tags/v1.1.0-rc1
Shivaram Lingamneni 5 년 전
부모
커밋
63502b8da4
1개의 변경된 파일2개의 추가작업 그리고 0개의 파일을 삭제
  1. 2
    0
      docs/MANUAL.md

+ 2
- 0
docs/MANUAL.md 파일 보기

@@ -619,6 +619,8 @@ HiddenServiceNonAnonymousMode 1
619 619
 HiddenServiceSingleHopMode 1
620 620
 ````
621 621
 
622
+Tor provides end-to-end encryption for hidden services, so there's no need to enable TLS in Oragono for the listener (`127.0.0.2:6668` in this example). Doing so is not recommended, given the difficulty in obtaining a TLS certificate valid for an .onion address.
623
+
622 624
 The second way is to run Oragono as a true hidden service, where the server's actual IP address is a secret. This requires hardening measures on the Oragono side:
623 625
 
624 626
 * Oragono should not accept any connections on its public interfaces. You should remove any listener that starts with the address of a public interface, or with `:`, which means "listen on all available interfaces". You should listen only on `127.0.0.1:6667` and a Unix domain socket such as `/hidden_service_sockets/oragono.sock`.

Loading…
취소
저장