Remove v3 onion secrets when transitioning to ssh over local #4794
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Status
Ready for review
Description of Changes
Fixes #4780 and fixes #4779.
Testing
Using a Tails prod setup (either VMs or hardware)
Install with default settings (ssh over tor, using v3 onion services)
set
enable_ssh_over_tor
to false, run./securedrop-admin install
v3 onion secrets (app-ssh.auth_private and mon-ssh.auth_private) are no longer in `install_files/ansible-base
I can ssh to both app and mon servers after transitioning to ssh over local
set
enable_ssh_over_tor
to true, run./securedrop-admin install
run
./securedrop-admin tailsconfig
I can ssh to app and mon servers over tor
Follow steps to reproduce in Playbook stalls when switching from SSH-over-Tor to SSH-over-LAN. #4779
This pr also closes Playbook stalls when switching from SSH-over-Tor to SSH-over-LAN. #4779
Deployment
This will be provided via the Ansible scripts delivered by git.
Checklist
If you made changes to the server application code:
make lint
) and tests (make -C securedrop test
) pass in the development containerIf you made changes to
securedrop-admin
:make -C admin test
) pass in the admin development containerIf you made changes to the system configuration:
If you made non-trivial code changes:
If you made changes to documentation:
make docs-lint
) passed locally