Re: Tor 0.2.2.22-alpha is out

2011-01-29 Thread Klaus Layer
> Tor 0.2.2.22-alpha fixes a few more less-critical security issues. The
> main other change is a slight tweak to Tor's TLS handshake that makes
> relays and bridges that run this new version reachable from Iran again.
> We don't expect this tweak will win the arms race long-term, but it will
> buy us a bit more time until we roll out a better solution.
> 
> Anybody running a relay or bridge who wants it to work for Iran should
> upgrade.
> 
Do you have any plans to apply these tweaks to the 2.1.X stable branch too?

Regards,

Klaus


signature.asc
Description: This is a digitally signed message part.


exit node config for egypt IP range

2011-01-28 Thread Klaus Layer
Hi,
Jacob Applebaum asked on twitter for more nodes which exit to ports 22, 25, 80
and 443 to support egypt. Does anyone can post a proper exit config for those 
who want to support the egypt people but are unfamiliar with exit nodes. I 
would like to open my relays exclusively for the egypt ip ranges.

Thanks,

Klaus


signature.asc
Description: This is a digitally signed message part.


Re: Tor relay on vserver exeeding numtcpsock

2011-01-13 Thread Klaus Layer
Am Mittwoch, 12. Januar 2011, um 22:44:12 schrieb Moritz Bartl:
> Hi,
> 
> You should probably contact the ISP first to see if they will raise the
> limit. Mine was low on file descriptors and they upped it generously 5
> minutes later (on a cheap $20 vserver).
> 
> Moritz
> 

Thanks for all your suggestions. This morning I contacted the HostEurope 
support. They were very friendly but refused to increase the parameter. They 
told me that the product is designed this way and they cannot change anything. 
They advised me to order a product with a higher number of tcp sockets. But 
even the high-end vserver product for EUR 70 ($90) per month only provides 
1550 tcp connections (http://faq.hosteurope.de/index.php?cpid=13281). All 
these HostEurope vserver products are crippled regarding numtcpsock.

Bottom line: HostEuropes vserver cannot be recommended for tor relays. I will 
update the wiki accordingly.

I will move to another ISP. In the meantime I will play around with the 
ConstrainedSocksSize parameter to get the most out of the vserver.

Moritz, from which ISP did you get this $20 vserver?

Regards,

Klaus

-- 
Klaus Layer
Walldorf, Germany
GPG Fingerprint: 466D 12F8 28A3 D137 A77E FC3B 271C 2D79 6F5E 94C9


signature.asc
Description: This is a digitally signed message part.


Tor relay on vserver exeeding numtcpsock

2011-01-12 Thread Klaus Layer
Hi all,

after running 2 tor relays over dialup connections for several weeks, I 
recently ordered a vserver (Hosteurope Virtual Server Linux L 4.0) and setup a 
middleman tor relay. Very fast the vserver run into shortage of tcp sockets 
which indicate lots of

"Error creating network socket: No buffer space available"

errors. The numtcpsocks parameter limit is set to 550 on the vserver. Before 
asking the ISP to increase the value I would like to ask you what a reasonable 
value  of this parameter would be. The tor wiki describe several parameters 
and values for SWSoft's Virtuozzo here 
https://trac.torproject.org/projects/tor/wiki/TheOnionRouter/TorFAQ#Virtualserver

but for numtcpsock a recommendation is missing.

Thanks for your help.

Klaus



-- 
Klaus Layer
Walldorf, Germany
GPG Fingerprint: 466D 12F8 28A3 D137 A77E FC3B 271C 2D79 6F5E 94C9


signature.asc
Description: This is a digitally signed message part.


Looking for updated debian sqeeze packages of Tor 0.2.1.28

2010-12-29 Thread Klaus Layer
Hi,

I am looking for updated debian sqeeze packages. Currently only Tor 0.2.1.26 
packages seems to be available. Any ideas where to find the 0.2.1.28 packages?

Thanks,

Klaus

-- 
Klaus Layer
Walldorf, Germany
GPG Fingerprint: 466D 12F8 28A3 D137 A77E FC3B 271C 2D79 6F5E 94C9


signature.asc
Description: This is a digitally signed message part.