You could then:
$ ssh ruminant@???
which Monkeysphere should be able to verify, as the host key for
president.bitfolk.com is published. One you've verified that you do
end up connected to the thing you expected to be connected to you
could sign the host key yourself and re-publish it, as at the moment
the entire thing relies on my single PGP key.
Hopefully soon I will be able to add DNSSEC to the bitfolk.com zone
and along with it I will publish SSHFP=B9 records for all the console
host mappings, so that will provide another (easier) way to verify,
if you're using a validating DNS resolver.
Cheers,
Andy
=B9 Dry details:
http://tools.ietf.org/html/rfc4255
An example of use:
http://benctechnicalblog.blogspot.co.uk/2011/03/sshfp-dns.html
--=20
> The optimum programming team size is 1.
Has Jurassic Park taught us nothing?
-- pfilandr
--YIwHDYD8sUXtBKvt
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)
iEYEAREDAAYFAk91GboACgkQIJm2TL8VSQsH1ACePc5KHwfhvXt2VkjIqa6XVxQg
+qYAoLBnwnVwiq6lNAvGDPBscqPfbnyJ
=r01a
-----END PGP SIGNATURE-----
--YIwHDYD8sUXtBKvt--
From andyparkins@??? Fri Mar 30 08:53:16 2012
Received: from mail-wg0-f52.google.com ([74.125.82.52])
by mail.bitfolk.com with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16)
(Exim 4.72) (envelope-from <andyparkins@???>)
id 1SDXa8-00016p-1j
for users@???; Fri, 30 Mar 2012 08:53:16 +0000
Received: by wgbgn7 with SMTP id gn7so321978wgb.21
for <users@???>; Fri, 30 Mar 2012 01:53:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
h=from:to:subject:date:user-agent:mime-version:content-type
:content-transfer-encoding:message-id;
bh=OtHy5r33SixntkCPtXBCDoFrZt/RTxf//w9DVKiD/n0=;
b=yKsCUQaqPHqCU4tyCoQmSXXJsdP2DD47lpMeiqMwHFzXnPWZzAGGraCQWlvR1+IzfJ
4oGmIcBxFuZosFDUIAo+ENUajcmsBYZdpT/XGzH+9pCQMMlSPoqRK6daJbZOW3QEyX3Z
FL9l7H8X/i3uOUQQ2EgH8E+98OTlmpErGlSrt5ROYiCnRiSJe3/roCtKpVRqrJJ4T/mk
IwQq//bP28Xo+N4Iw+X4tDqFz6GWinyT5Gh0wUDWbKPUGKzY3m6oAWMDfc7z4P9LMpR9
BZBoPkYxBno1/GOABGuqlvuTS6NRfmLiDHx+6+PYv5+bd0A+T09aEmon1YjxRe7lVQfH
/a5Q==
Received: by 10.180.101.136 with SMTP id fg8mr4379161wib.4.1333097589563;
Fri, 30 Mar 2012 01:53:09 -0700 (PDT)
Received: from dvr.localnet (mail.360visiontechnology.com. [92.42.121.178])
by mx.google.com with ESMTPS id o2sm7549934wiv.11.2012.03.30.01.53.07
(version=TLSv1/SSLv3 cipher=OTHER);
Fri, 30 Mar 2012 01:53:07 -0700 (PDT)
From: Andy Parkins <andyparkins@???>
To: users@???
Date: Fri, 30 Mar 2012 09:52:48 +0100
User-Agent: KMail/1.13.6 (Linux/3.0.0-1-686-pae; KDE/4.6.3; i686; ; )
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="nextPart4806720.cC54R76npF";
protocol="application/pgp-signature"; micalg=pgp-sha1
Content-Transfer-Encoding: 7bit
Message-Id: <201203300952.59944.andyparkins@???>
X-Virus-Scanner: Scanned by ClamAV on mail.bitfolk.com at Fri,
30 Mar 2012 08:53:16 +0000
X-SA-Exim-Connect-IP: 74.125.82.52
X-SA-Exim-Mail-From: andyparkins@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
spamd0.lon.bitfolk.com
X-Spam-Level:
X-Spam-ASN: AS15169 74.125.0.0/16
X-Spam-Status: No, score=-0.8 required=5.0 tests=DKIM_SIGNED,DKIM_VALID,
DKIM_VALID_AU, RCVD_IN_DNSWL_LOW,
SPF_PASS shortcircuit=no autolearn=disabled version=3.3.1
X-Spam-Report: * -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/,
low * trust * [74.125.82.52 listed in list.dnswl.org]
* -0.0 SPF_PASS SPF: sender matches SPF record
* -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's * domain
* -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
* 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
* valid
X-SA-Exim-Version: 4.2.1 (built Wed, 25 Jun 2008 17:14:11 +0000)
X-SA-Exim-Scanned: Yes (on mail.bitfolk.com)
Subject: [bitfolk] Bitcoin as payment method
X-BeenThere: users@???
X-Mailman-Version: 2.1.11
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
<mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
<mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Fri, 30 Mar 2012 08:53:16 -0000
--nextPart4806720.cC54R76