diff options
| author | Xe Iaso <me@xeiaso.net> | 2025-01-19 08:36:20 -0500 |
|---|---|---|
| committer | Xe Iaso <me@xeiaso.net> | 2025-01-19 08:36:20 -0500 |
| commit | 9a57488137f156835a45c1ce2246af6c946793bb (patch) | |
| tree | 43a1b7b6b4036a7dcc70d2de34150bbc3a77a857 | |
| parent | 6a3ce167da2d2b02f772418576d32b00f25e1b44 (diff) | |
| download | x-9a57488137f156835a45c1ce2246af6c946793bb.tar.xz x-9a57488137f156835a45c1ce2246af6c946793bb.zip | |
cmd/anubis: add info about key fingerprint being the input to the challenge
Signed-off-by: Xe Iaso <me@xeiaso.net>
| -rw-r--r-- | cmd/anubis/README.md | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/cmd/anubis/README.md b/cmd/anubis/README.md index bbfe795..22dd94d 100644 --- a/cmd/anubis/README.md +++ b/cmd/anubis/README.md @@ -137,6 +137,7 @@ Challenges are formed by taking some user request metadata and using that to gen - `X-Real-Ip`: The IP address of the requestor, as set by a reverse proxy server. - `User-Agent`: The user agent string of the requestor. - The current time in UTC rounded to the nearest week. +- The fingerprint (checksum) of Anubis' private ED25519 key. This forms a fingerprint of the requestor using metadata that any requestor already is sending. It also uses time as an input, which is known to both the server and requestor due to the nature of linear timelines. Depending on facts and circumstances, you may wish to disclose this to your users. |
