aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorXe Iaso <me@xeiaso.net>2025-01-19 08:36:20 -0500
committerXe Iaso <me@xeiaso.net>2025-01-19 08:36:20 -0500
commit9a57488137f156835a45c1ce2246af6c946793bb (patch)
tree43a1b7b6b4036a7dcc70d2de34150bbc3a77a857
parent6a3ce167da2d2b02f772418576d32b00f25e1b44 (diff)
downloadx-9a57488137f156835a45c1ce2246af6c946793bb.tar.xz
x-9a57488137f156835a45c1ce2246af6c946793bb.zip
cmd/anubis: add info about key fingerprint being the input to the challenge
Signed-off-by: Xe Iaso <me@xeiaso.net>
-rw-r--r--cmd/anubis/README.md1
1 files changed, 1 insertions, 0 deletions
diff --git a/cmd/anubis/README.md b/cmd/anubis/README.md
index bbfe795..22dd94d 100644
--- a/cmd/anubis/README.md
+++ b/cmd/anubis/README.md
@@ -137,6 +137,7 @@ Challenges are formed by taking some user request metadata and using that to gen
- `X-Real-Ip`: The IP address of the requestor, as set by a reverse proxy server.
- `User-Agent`: The user agent string of the requestor.
- The current time in UTC rounded to the nearest week.
+- The fingerprint (checksum) of Anubis' private ED25519 key.
This forms a fingerprint of the requestor using metadata that any requestor already is sending. It also uses time as an input, which is known to both the server and requestor due to the nature of linear timelines. Depending on facts and circumstances, you may wish to disclose this to your users.