瀏覽代碼

Note about flakiness

Bob Mottram 8 年之前
父節點
當前提交
a9a2ade4cc
共有 2 個檔案被更改,包括 22 行新增16 行删除
  1. 2
    0
      doc/EN/domains.org
  2. 20
    16
      website/EN/domains.html

+ 2
- 0
doc/EN/domains.org 查看文件

@@ -24,6 +24,8 @@ You probably only need one ICANN domain name and then the various Freedombone ap
24 24
 
25 25
 You will also need a dynamic DNS account, and again this might be something you have to pay a subscription for. Your Freedombone system will have a local network address (typically 192.168.x.y or 10.x.y.z) and also a public IP address assigned by your ISP. Your ISP will change your public IP address every so often (that's why it's called "dynamic") and so there needs to be some way to link the domain name which you've obtained to your changing public IP address. That's what the dynamic DNS service does.
26 26
 
27
+/Starting to think that this sounds like a rather shaky system which would would be not too difficult for an adversary to disrupt - especially if they get cosy with ICANN or the dynamic DNS provider? You'd be right. But moving swiftly past that man behind a curtain.../
28
+
27 29
 In simple terms what happens is that on a regular basis the Freedombone system will ping the dynamic DNS service and say "/this is my current public IP address/", so that the mapping between domain name and IP address can be maintained.
28 30
 
29 31
 The dynamic DNS service will have their own DNS servers maintaining the IP address mappings and so on the web site where you registered your domain name you will need to specify the servers of the your dynamic DNS account. Look for an option such as "/change nameservers/" or "/custom nameservers/", remove any names which might already be there and then add the servers used by the dynamic DNS service. For example, if you're using FreeDNS then these servers would be:

+ 20
- 16
website/EN/domains.html 查看文件

@@ -3,7 +3,7 @@
3 3
 "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
4 4
 <html xmlns="http://www.w3.org/1999/xhtml" lang="en" xml:lang="en">
5 5
 <head>
6
-<!-- 2016-11-29 Tue 10:53 -->
6
+<!-- 2016-11-29 Tue 14:07 -->
7 7
 <meta http-equiv="Content-Type" content="text/html;charset=utf-8" />
8 8
 <meta name="viewport" content="width=device-width, initial-scale=1" />
9 9
 <title></title>
@@ -245,9 +245,9 @@ for the JavaScript code in this tag.
245 245
 
246 246
 <center><h1>How to get a domain name</h1></center>
247 247
 
248
-<div id="outline-container-orgc34c8b8" class="outline-2">
249
-<h2 id="orgc34c8b8">The domain name itself</h2>
250
-<div class="outline-text-2" id="text-orgc34c8b8">
248
+<div id="outline-container-orgc0e9971" class="outline-2">
249
+<h2 id="orgc0e9971">The domain name itself</h2>
250
+<div class="outline-text-2" id="text-orgc0e9971">
251 251
 <p>
252 252
 If you want your sites or chat systems to be available via an ordinary web browser (i.e. not a Tor browser) then you'll need to obtain a domain name. The domain name system is ultimately controlled by ICANN and to obtain a domain name for which you can also get a TLS certificate you'll need to buy one. There are various sites which sell domain names, and fortunately they can often be quite cheap - especially if you can think of an obscure name for your site. Prefer sites where the domain name subscription can be automatically renewed, because otherwise trolls can quickly buy your domain when it expires and then hold it for ransom. If you're planning to self-host for more than an ephemeral purpose, such as a conference or festival, then choose the longest subscription period you can afford (typically a few years).
253 253
 </p>
@@ -258,14 +258,18 @@ You probably only need one ICANN domain name and then the various Freedombone ap
258 258
 </div>
259 259
 </div>
260 260
 
261
-<div id="outline-container-org0ae0f49" class="outline-2">
262
-<h2 id="org0ae0f49">Dynamic DNS</h2>
263
-<div class="outline-text-2" id="text-org0ae0f49">
261
+<div id="outline-container-orge197a4d" class="outline-2">
262
+<h2 id="orge197a4d">Dynamic DNS</h2>
263
+<div class="outline-text-2" id="text-orge197a4d">
264 264
 <p>
265 265
 You will also need a dynamic DNS account, and again this might be something you have to pay a subscription for. Your Freedombone system will have a local network address (typically 192.168.x.y or 10.x.y.z) and also a public IP address assigned by your ISP. Your ISP will change your public IP address every so often (that's why it's called "dynamic") and so there needs to be some way to link the domain name which you've obtained to your changing public IP address. That's what the dynamic DNS service does.
266 266
 </p>
267 267
 
268 268
 <p>
269
+<i>Starting to think that this sounds like a rather shaky system which would would be not too difficult for an adversary to disrupt - especially if they get cosy with ICANN or the dynamic DNS provider? You'd be right. But moving swiftly past that man behind a curtain&#x2026;</i>
270
+</p>
271
+
272
+<p>
269 273
 In simple terms what happens is that on a regular basis the Freedombone system will ping the dynamic DNS service and say "<i>this is my current public IP address</i>", so that the mapping between domain name and IP address can be maintained.
270 274
 </p>
271 275
 
@@ -286,9 +290,9 @@ It might take a few minutes for the changes to take effect, so don't be too hast
286 290
 </p>
287 291
 </div>
288 292
 
289
-<div id="outline-container-org6097019" class="outline-3">
290
-<h3 id="org6097019">Configuring with FreeDNS</h3>
291
-<div class="outline-text-3" id="text-org6097019">
293
+<div id="outline-container-org93cf4d2" class="outline-3">
294
+<h3 id="org93cf4d2">Configuring with FreeDNS</h3>
295
+<div class="outline-text-3" id="text-org93cf4d2">
292 296
 <p>
293 297
 If you are using FreeDNS as a dynamic DNS provider then on their site select "<i>Domains</i>" and add your domain name (this might only be available to paid subscribers). Make sure that they're marked as "<i>private</i>" so that subdomains of your domain name are not used by other users of the site.
294 298
 </p>
@@ -300,18 +304,18 @@ Select "Subdomains" from the menu on the left then select the MX entry for your
300 304
 </div>
301 305
 </div>
302 306
 
303
-<div id="outline-container-org6ca3626" class="outline-2">
304
-<h2 id="org6ca3626">Setting up with Freedombone</h2>
305
-<div class="outline-text-2" id="text-org6ca3626">
307
+<div id="outline-container-org6794f2a" class="outline-2">
308
+<h2 id="org6794f2a">Setting up with Freedombone</h2>
309
+<div class="outline-text-2" id="text-org6794f2a">
306 310
 <p>
307 311
 When you start the base installation of the system it will ask you to choose a dynamic DNS provider and then enter the login details for the dynamic DNS service.
308 312
 </p>
309 313
 </div>
310 314
 </div>
311 315
 
312
-<div id="outline-container-orgfc5c0d9" class="outline-2">
313
-<h2 id="orgfc5c0d9">A note about Tor</h2>
314
-<div class="outline-text-2" id="text-orgfc5c0d9">
316
+<div id="outline-container-org495e9ff" class="outline-2">
317
+<h2 id="org495e9ff">A note about Tor</h2>
318
+<div class="outline-text-2" id="text-org495e9ff">
315 319
 <p>
316 320
 If you only want your sites to be available via Tor then none of the above is needed and you can access your sites and systems via their onion addresses. Tor has its own naming system which is independent from ICANN, and you also won't need TLS/SSL certificates since it also manages transport encryption itself. When building disk images use the <b>&#x2013;onion yes</b> option, or choose one of the ready made onion disk images <a href="./downloads">from downloads</a>.
317 321
 </p>