Index | Thread | Search

From:
Renaud Allard <renaud@allard.it>
Subject:
Re: [new] security/certspotter 0.16.0
To:
ports@openbsd.org
Date:
Wed, 14 Feb 2024 15:06:07 +0100

Download raw body.

Thread

On 2/14/24 15:02, Stuart Henderson wrote:
> On 2024/02/14 08:43, Ian Darwin wrote:
>> On 2/14/24 07:07, Stuart Henderson wrote:
>>> ooof, this uses a *lot* of bandwidth!
>>>
>>  From the man page:
>>
>>> -start_at_end
>>>
>>> : Start monitoring logs from the end rather than the beginning.
>>>
>>> |**WARNING**: monitoring from the beginning guarantees detection of all
>>> certificates, but requires downloading hundreds of millions of
>>> certificates, which takes days. |
> 
> It's downloaded about 1TB of data so far and looking at the
> */healthchecks/*.txt files; some of the CT logs are less than 1% of the
> way in.
> 
> I think it might be a good idea to set that flag by default in the
> rc script, but if we do that it seems you can't override an existing
> default daemon_flags with a "no flags" setting with rc.subr so I don't
> think you can then un-set it.
> 

Ah, sorry, I got your reply just after I answered former post.
That flag doesn't change anything, except it will download newer certs 
first instead of older ones. It will use the same bandwidth whatever 
option you choose.