Add krynox.net.domain-verification template#1455
Open
fahmikemal wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
New template for Krynox (
krynox.net) — a privacy-first, proof-of-work CAPTCHA service. The template lets a Krynox customer prove control of the domain they want to protect by adding the_krynox-challengeTXT record that Krynox checks, in one click via Domain Connect instead of copy-pasting DNS.Single synchronous record: a
_krynox-challengeTXT holdingkrynox-verify=%token%, where%token%is the one-time verification value Krynox generates per domain.Type of change
How Has This Been Tested?
<providerId>.<serviceId>.jsonlogoUrlis actually served by a webserverChecklist of common problems
syncPubKeyDomainis set — set tokrynox.net; the public key is published at_dcpubkeyv1.krynox.net.warnPhishingis not set alongsidesyncPubKeyDomain—warnPhishingis not present.syncRedirectDomainis set whenever the template usesredirect_uriin the synchronous flow — N/A; the template has noredirect_uri, and applies are digitally signed so an unsigned open-redirect is not possible."v=spf1 ...") — the only TXT iskrynox-verify=%token%.txtConflictMatchingModeis set on every TXT record that must be unique — set toPrefixwithtxtConflictMatchingPrefixkrynox-verify=so a re-apply replaces the verification record.krynox-verify=%token%, not a bare%token%.hostlabel — the host is the fixed label_krynox-challenge.hostfield to create a subdomain — the host contains no variable.%host%does not appear explicitly in anyhostattribute — correct.essentialis set toOnApplyon records the end user may need to modify or remove — N/A; the verification TXT must remain in place (Krynox re-checks it), so it staysessential: Always.Online Editor test results
Editor test link(s):
app): Test krynox.net/domain-verification example.com/app