Skip to content
Snippets Groups Projects
Commit 0906dde9 authored by David Goulet's avatar David Goulet :panda_face: Committed by George Kadianakis
Browse files

man: Document HSv3 client authorization revocation


Removing a ".auth" file revokes a client access to the service but the
rendezvous circuit is not closed service side because the service simply
doesn't know which circuit is for which client.

This commit notes in the man page that to fully revoke a client access to the
service, the tor process should be restarted.

Closes #28275

Signed-off-by: David Goulet's avatarDavid Goulet <dgoulet@torproject.org>
parent 1a97379e
No related branches found
No related tags found
No related merge requests found
o Documentation (hidden service v3, man page):
- Note in the man page that the only real way to fully revoke an onion
service v3 client authorization is by restarting the tor process. Closes
ticket 28275.
......@@ -2961,6 +2961,10 @@ Note that once you've configured client authorization, anyone else with the
address won't be able to access it from this point on. If no authorization is
configured, the service will be accessible to anyone with the onion address.
Revoking a client can be done by removing their ".auth" file, however the
revocation will be in effect only after the tor process gets restarted even if
a SIGHUP takes place.
See the Appendix G in the rend-spec-v3.txt file of
https://spec.torproject.org/[torspec] for more information.
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment