Index | Thread | Search

From:
Stuart Henderson <stu@spacehopper.org>
Subject:
Re: [new] security/certspotter 0.16.0
To:
Ian Darwin <ian@darwinsys.com>
Cc:
ports@openbsd.org
Date:
Wed, 14 Feb 2024 14:02:34 +0000

Download raw body.

Thread
On 2024/02/14 08:43, Ian Darwin wrote:
> On 2/14/24 07:07, Stuart Henderson wrote:
> > ooof, this uses a *lot* of bandwidth!
> > 
> From the man page:
> 
> > -start_at_end
> > 
> > : Start monitoring logs from the end rather than the beginning.
> > 
> > |**WARNING**: monitoring from the beginning guarantees detection of all
> > certificates, but requires downloading hundreds of millions of
> > certificates, which takes days. |

It's downloaded about 1TB of data so far and looking at the
*/healthchecks/*.txt files; some of the CT logs are less than 1% of the
way in.

I think it might be a good idea to set that flag by default in the
rc script, but if we do that it seems you can't override an existing
default daemon_flags with a "no flags" setting with rc.subr so I don't
think you can then un-set it.

Hmm.