[tor-relays] Loss of Stable flag

2021-11-15 Thread Arlen Yaroslav via tor-relays
Hello to all relay operators!

My relay Deepsky (09A70E396DE93F54D4541BBB0EC8E2B23761F34F) has not been 
receiving the 'Stable' flag from the DA consensus. Up until recently (the past 
month or so) it had been assigned the full complement of flags. Nothing has 
been changed on the server and I am not aware of any issues. Would any of the 
directory authority operators be able to shed light on why some of the DAs are 
not assigning it the flag?

Thanks!
___
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays


Re: [tor-relays] Compression bomb from dizum

2021-11-15 Thread David Goulet
On 06 Nov (21:39:44), Logforme wrote:
> Got the following in my log today:
> Nov 06 18:19:01.000 [warn] Possible compression bomb; abandoning stream.
> Nov 06 18:19:01.000 [warn] Unable to decompress HTTP body (tried Zstandard
> compressed, on Directory connection (client reading) with 45.66.33.45:80).
> 45.66.33.45 is tor.dizum.com, a Tor directory authority.
> 
> False positive or a problem generating directory info at dizum?

I would think false positive here considering that it comes from "dizum".

Lets keep an eye out for more though.

Thanks!
David

-- 
smhtN6GS89mA/K6UVSGViMyg06C3llc28/cEM0NvTcI=


signature.asc
Description: PGP signature
___
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays


Re: [tor-relays] Hardware requirements for a fast Tor relay

2021-11-15 Thread Elias via tor-relays
-BEGIN PGP SIGNED MESSAGE-

Hash: SHA256

>Since this is virtualization, make sure that features such as AES

>acceleration are active.

Yes, I have tested that. Is active.

>The number of cores is not really relevant since Tor is not

>multi-threaded. The EPYC 7702 can boost up to 3.35 GHz, check that it

>reaches that under load.

It actually reaches the frequency under load.

Unfortunately, the one core is now fully under load.

My Relay moved 5TB today, with an average bandwidth of 500Mbit.

The average load according to HTOP is now just over 1.0, which is fine for a 
dual core.

However, one core is loaded to 100%. So far, there are no error messages and I 
achieve a stable 40MB/s with peaks of up to 50MB/s.

But my Relay is only a few days old. Advertised Bandwith is currently at just 
over 30 MiB, but that will change soon.

I'm afraid the CPU won't do much more, but with 500Mbit/s I'm among the fastest 
Relays at this hoster. Directly on page 1.

Let's see if I can tune a bit, otherwise I'll just let it run as long as no 
errors appear.

>Also since you have 2 cores, you can run two instances of Tor.

Yes, I know. However, the DirAuths then have more work to do because they have 
to add another Relay to the Consensus.

Everything has advantages and disadvantages. Let's see what I do.

>> I chose this server because the bandwith is unmetered and it's a

>> guaranteed 1GHz link.

>I assume you mean 1 Gbit/s.

Yes, that was a typo.

By the way, can someone explain to me how to reply directly to a reply in a 
thread without my reply just appearing at the bottom?

I'm new to this list and haven't quite figured it out yet. I hope you 
understand what I mean - I want my replies to be indented correctly. Thanks!

Have a great weekend, everyone!

-BEGIN PGP SIGNATURE-

iQIzBAEBCAAdFiEElcZnZFMJSyKcTts0q6Mz3/Qy4d0FAmGO/j0ACgkQq6Mz3/Qy

4d395A/+NDRe7IhCbsmgWCUM2Li1XnoN4g3Z091T+U1QPQg7kCvibXXeiHhgs/jP

und/63N7FM3OmHi/WUPerK4qfk5lssRU0OPvyAApIzruCTBDj2TuCdpagsfNRQCU

QFE162q/cUvwRDyoNHVXxhSk8Bvtwj6Mxw4oE5p6yJFvBgSjT7uHGZgAgHobs/QH

zgCKsoEI3H0Wj8kYtxfP9xlhDe1XNidaGIXe5axFlcraw2/f7LXhG7BPJ2XaQHsp

CCPFOoLt3Ggpl3AFyIT/UYJ+2e/y+RJXSy71ptew0Xl3MQXv8j5avpo1zmDFXYqV

4SYbjzqmn/5t/O5QPprTBDVr2+SgkjNoFJWFTFK5R7jjqqGvs9fzbAXV6XGOKBeC

F6aRs/caQiJ57gAJmYdUW9dQubeIulR0yUlQlwXWWdAPEduLP3B8MxDtEuFOYHWL

h+C3I1tlPp+DFE3hfPARW1hX8DGBtA8pH6MKwn6onJh65mWv6f7pmU8LQHbuPPmw

w7o7qZHuXxhFSoxPRklISr0BjcLG94DHGWlD2UMyxpU/m3745+JGHhqlTJX+/aeN

HHWJ9FN1beI4YHfeUHBgicEx8pywtHK/l6vi5v9rrzko7nbYwG4SayrsgrpXqz6F

ifqCNzouxpjVs7MvuTDPIC62mNLED7Zop3tsMwdnyRZJc8Lm3Uo=

=Gm4l

-END PGP SIGNATURE-

___
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays


Re: [tor-relays] Question about IPv6

2021-11-15 Thread lists
On Wednesday, November 10, 2021 6:08:47 AM CET xplato via tor-relays wrote:

> I have three relays running Hardened BSD hosted at Frantech. They do not
> offer support for setting up IPv6. I am not sure how to accomplish this and
> wondered if anyone would have insight into setting this up? I have not
> found much in the way of instruction. A resource that provides instructions
> would be much appreciated.

Maybe this helps. A working Debian config @frantec/BuyVM

Login to Stallion: https://manage.buyvm.net/login
-> Networking -> IPv6 -> Assign IPv6 Address(es)
After that you see your gateway under Network Settings
(The settings symbol @bottom right)

Set Reverse DNS if you want for IP and IPv6.

You have to 'Graceful Restart' the KVM if you have changed something in the 
Stallion network config.

/etc/network/interfaces
#

# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

source /etc/network/interfaces.d/*

# The loopback network interface
auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
iface eth0 inet static
address 104.244.73.193
netmask 255.255.255.255
gateway 104.244.73.1
# dns-* options are implemented by the resolvconf package, if installed
dns-nameservers 127.0.0.1 107.189.0.68 107.189.0.69
dns-search for-privacy.net

iface eth0 inet6 static
address 2605:6400:0030:f7ca::2
netmask 64
post-up  ip -6 route add 2605:6400:0030::1 dev eth0
post-up  ip -6 route add default via 2605:6400:0030::1
pre-down ip -6 route del default via 2605:6400:0030::1
pre-down ip -6 route del 2605:6400:0030::1 dev eth0
dns-nameservers ::1 2a05:fc84::42 2a05:fc84::43

###

Hint dns-nameservers:
I use unbound as local resolver. IPv4 ns are frantec's and IPv6 ns (Francisco 
has no IPv6 ns) are from Digitale Gesellschaft (CH)
https://www.digitale-gesellschaft.ch/dns/

There is also very good, competent help on IRC #frantec
https://wiki.buyvm.net/doku.php/irc/main
is mirrored to Discord
https://buyvm.net/beware-the-moshbear/


-- 
╰_╯ Ciao Marco!

Debian GNU/Linux

It's free software and it gives you freedom!

signature.asc
Description: This is a digitally signed message part.
___
tor-relays mailing list
tor-relays@lists.torproject.org
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays