X-Git-Url: https://git.distorted.org.uk/~mdw/zones/blobdiff_plain/5a33b1782deb8db9e238b66528811ae21be2c2c1..098020adcf7cf4460680280e9ca79c00d24e9dcd:/distorted.lisp diff --git a/distorted.lisp b/distorted.lisp index 9a1f43e..57a7225 100644 --- a/distorted.lisp +++ b/distorted.lisp @@ -138,6 +138,15 @@ (jump :svc jazz.jump :sshfp "jazz")) ((git www mail) (colo :svc stratocaster.colo :sshfp "stratocaster") (jump :svc stratocaster.jump :sshfp "stratocaster")) + ((www @) :tlsa (:https (:service-certificate-constraint + :certificate :sha-256 #p"http-server-www#1"))) + (git :tlsa (:https (:trust-anchor-assertion + :certificate :sha-256 #p"distorted-ca"))) + (www-cache :tlsa (3127 (:trust-anchor-assertion + :certificate :sha-256 #p"distorted-ca"))) + (mail :tlsa ((:smtp :submission :imap) + (:trust-anchor-assertion + :certificate :sha-256 #p"distorted-ca"))) :svc #+view/inside stratocaster.colo #-view/inside stratocaster.jump (cabal :svc stratocaster.colo :sshfp "stratocaster") @@ -216,13 +225,14 @@ (firebird :cname firebird.dhcp) (marauder :cname marauder.dhcp) (invader :cname invader.dhcp) + (gretsch :cname gretsch.dhcp) ;; Virtual network. (vpn :net vpn) (crybaby (vpn :addr crybaby.vpn :sshfp "crybaby")) (terror (vpn :addr terror.vpn :sshfp "terror")) (orange (vpn :addr orange.vpn :sshfp "orange")) - (haze (vpn :addr haze.vpn)) + (haze (vpn :addr haze.vpn :sshfp "haze")) (iodine :net iodine) ;; ITS.