Finish setting up the Sandstorm instance
For now, since our Sandstorm installation rather heavily relies on Debian Jessie features, and our VM hosting provider has some problem with their virtualisation infrastructure, weasel and I have agreed that it's not possible to move the Sandstorm instance at http://para.noid.cat to a TPO-controlled server.
However, and despite my putting a GIANT, ALL-CAPS WARNING THAT MY SERVER HAS ZERO TRANSPORT LAYER ENCRYPTION AND THE SANDSTORM INSTANCE SHOULDN'T BE USED FOR ACTUAL, SENSITIVE TOR PROJECT DOCUMENTS AND RESOURCES YET in my email announcing our Sandstorm instance, some people have already started doing exactly that. Ergo, this thing needs TLS now (or needed it yesterday!).
Because we can't easily relocate to a TPO-controlled server immediately, weasel and I have agreed that likely the most sensible thing to do would be to:
- Point the
storm.torproject.org
and other required DNS entries at my server. - Purchase TLS certificates for
*.storm.torproject.org
andstorm.torproject.org
.