[tor-bugs] #27680 [Webpages/Website]: Explain how to use auth cookie for onion services

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Oct 12 22:08:30 UTC 2018


#27680: Explain how to use auth cookie for onion services
------------------------------+--------------------------------
 Reporter:  traumschule       |          Owner:  traumschule
     Type:  enhancement       |         Status:  needs_revision
 Priority:  Medium            |      Milestone:
Component:  Webpages/Website  |        Version:
 Severity:  Normal            |     Resolution:
 Keywords:                    |  Actual Points:
Parent ID:                    |         Points:
 Reviewer:                    |        Sponsor:
------------------------------+--------------------------------
Changes (by traumschule):

 * status:  needs_review => needs_revision


Comment:

 IRC: why isn't HiddenServiceAuthorizeClient supported on onion 3 addresses

 asn:
 it actually is, but it works differently
 we might want to add a blurb when someone starts up v3 with
 HiddenServiceAuthorizeClient to point out to the way it should be done
 you need to use latest master and check the man page for
 'authorized_clients'
 it's in the last part of it "Client Authorization" marked as "(Version 3
 only)"
 it's still experimental, so you need to generate the keys yourself :)
 see https://github.com/haxxpop/torkeygen

 mtigas:
 i'm going to try to submit a patch/pr for some man page rewording about
 that this weekend.
 if you're using 0.3.5.x by having an authorized_clients dir with valid
 .auth files in the hiddenservicedir, tor will enable auth for that onion.
 i've got an alternate key generating script here; at worst it has some
 more explicit instructions for setup:
 https://gist.github.com/mtigas/9c2386adf65345be34045dace134140b

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/27680#comment:6>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list