Commit e84d695
fix(site): one key per name, not one per ending (#253)
`keyPaths` keyed certificates off the TLD, justified as "that is the
granularity the registry stores". It is the opposite of what the registry
stores. Migration 009 says so, and says why:
Per name rather than per TLD, and that is forced by 008: names under a
TLD are sold, so `blue.eggs` can belong to someone who does not own
`.eggs`. Hanging keys off the TLD would let its operator publish a key
for a name they already sold.
A shared per-ending key is that hole in private-key form. The ending's
operator holds the key for every name they sold, and every buyer holds a
key that signs for every other buyer. 009 closed it at the pin layer;
this reintroduced it one layer down, where it is worse — a pin can be
withdrawn, a distributed private key cannot.
The certificate carried `DNS:*.<tld>` for the same reason, so each
buyer's certificate asserted authority over every other name in a
namespace they merely bought into. Now `DNS:<name>` alone.
Found because it broke nginx on a live box: `moshcode site` wrote
conf.d blocks pointing at /etc/ssl/moshpit/hacker.crt while the
certificates on disk were per-name, so `nginx -t` failed with three
missing files and the box could not reload. Per-name paths agree with
what setup-origin.sh has written all along.
Path sanitising now keeps dots, so `alt.2600` stays `alt.2600.crt`.
Runs of dots collapse to one, so no `..` survives to mean "parent":
`../../etc/passwd` becomes `etcpasswd`, a harmless filename inside the
key directory.
841 tests pass.
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>1 parent 11e8586 commit e84d695
3 files changed
Lines changed: 64 additions & 24 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
49 | 49 | | |
50 | 50 | | |
51 | 51 | | |
52 | | - | |
| 52 | + | |
53 | 53 | | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
58 | 74 | | |
59 | | - | |
60 | | - | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
61 | 82 | | |
62 | 83 | | |
63 | 84 | | |
| |||
80 | 101 | | |
81 | 102 | | |
82 | 103 | | |
83 | | - | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
84 | 108 | | |
85 | | - | |
| 109 | + | |
86 | 110 | | |
87 | 111 | | |
88 | 112 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
253 | 253 | | |
254 | 254 | | |
255 | 255 | | |
256 | | - | |
| 256 | + | |
257 | 257 | | |
258 | 258 | | |
259 | 259 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
53 | 49 | | |
54 | 50 | | |
55 | | - | |
56 | | - | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
57 | 69 | | |
58 | 70 | | |
| 71 | + | |
59 | 72 | | |
60 | 73 | | |
61 | 74 | | |
62 | 75 | | |
63 | | - | |
64 | | - | |
| 76 | + | |
| 77 | + | |
65 | 78 | | |
66 | 79 | | |
67 | 80 | | |
68 | 81 | | |
69 | | - | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
70 | 86 | | |
71 | 87 | | |
72 | 88 | | |
| |||
0 commit comments