On Tue, Jan 26, 2016 at 08:52:29PM +0100, Guus Sliepen wrote: > > My intention was to sign the content of export-all with the nodes' public > > key, which would require the corresponding private key to verify. > > > > Does this make sense ? > > Yes, that does make a lot of sense. I'll see if I can add a safe way to > sign/verify arbitrary data with the tinc command.
I totally should've spent my time on other things on the TODO list for
tinc 1.1, but I've just added this functionality (it's in the git
repository). You can now do:
Server: tinc export-all | tinc sign > all.signed
Client: tinc verify server all.signed | tinc import
You have to specify a node name when verifying data ("server" in the
example above), only a signature made by that node will be accepted, or
you have to specify "*" to allow signatures by any known node. Also, "."
is shorthand for the local node. Let me know if this is what you wanted.
--
Met vriendelijke groet / with kind regards,
Guus Sliepen <[email protected]>
signature.asc
Description: Digital signature
_______________________________________________ tinc mailing list [email protected] http://www.tinc-vpn.org/cgi-bin/mailman/listinfo/tinc
