X-Git-Url: https://git.distorted.org.uk/~mdw/zones/blobdiff_plain/5a33b1782deb8db9e238b66528811ae21be2c2c1..d9fb28388e718248637aec1e28bdb681611f6a9b:/distorted.lisp diff --git a/distorted.lisp b/distorted.lisp index 9a1f43e..5dde19a 100644 --- a/distorted.lisp +++ b/distorted.lisp @@ -138,6 +138,18 @@ (jump :svc jazz.jump :sshfp "jazz")) ((git www mail) (colo :svc stratocaster.colo :sshfp "stratocaster") (jump :svc stratocaster.jump :sshfp "stratocaster")) + ((www @) :tlsa (:https (:service-certificate-constraint + :certificate :sha-256 + #p"certs/http-server-www#1.cert"))) + (git :tlsa (:https (:trust-anchor-assertion + :certificate :sha-256 + #p"certs/distorted-ca.cert"))) + (www-cache :tlsa (3127 (:trust-anchor-assertion + :certificate :sha-256 + #p"certs/distorted-ca.cert"))) + (mail :tlsa ((:smtp :submission :imap) (:trust-anchor-assertion + :certificate :sha-256 + #p"certs/distorted-ca.cert"))) :svc #+view/inside stratocaster.colo #-view/inside stratocaster.jump (cabal :svc stratocaster.colo :sshfp "stratocaster") @@ -222,7 +234,7 @@ (crybaby (vpn :addr crybaby.vpn :sshfp "crybaby")) (terror (vpn :addr terror.vpn :sshfp "terror")) (orange (vpn :addr orange.vpn :sshfp "orange")) - (haze (vpn :addr haze.vpn)) + (haze (vpn :addr haze.vpn :sshfp "haze")) (iodine :net iodine) ;; ITS.