[Cryptech Tech] Some problems with the repo access

Randy Bush randy at psg.com
Fri Feb 14 08:03:33 UTC 2014


> We should at least do TLSA (3 1 1) for the website:
> 
> _443._tcp.cryptech.is. IN TLSA 3 1 1 b348d66d3e8b24437a9857bb3210ffd503f7e3f97a481d97bc07306870aa8873

agree.  would if i could

zone "cryptech.is" { type slave; file "secondary/is.cryptech";
     masters { 193.10.5.91; 193.11.20.167; }; };

please tell me these do not violate 2182

> and enable strict transport security so that people will use HTTPS forever.

i have no problem with that

randy



More information about the Tech mailing list