From 5ebb546d581c2d8b7cac1262cf9acf8c6022a804 Mon Sep 17 00:00:00 2001
From: Evgeny Poberezkin <2769109+epoberezkin@users.noreply.github.com>
Date: Sun, 6 Jun 2021 11:20:06 +0100
Subject: [PATCH 1/5] remove digitalocean deployment until ready (#157)
---
README.md | 17 +----------------
img/digitalocean.png | Bin 0 -> 2569 bytes
img/digitalocean.svg | 1 -
3 files changed, 1 insertion(+), 17 deletions(-)
create mode 100644 img/digitalocean.png
delete mode 100644 img/digitalocean.svg
diff --git a/README.md b/README.md
index cfd9e96c4..b00276e71 100644
--- a/README.md
+++ b/README.md
@@ -50,7 +50,7 @@ See [simplex-chat](https://github.com/simplex-chat/simplex-chat) terminal UI for
## Using SMP server and SMP agent
-You can either run your own SMP server locally or deploy using Linode or DigitalOcean recipe, or try local SMP agent with the deployed demo server:
+You can either run your own SMP server locally or deploy using [Linode StackScript](#deploy-smp-server-on-linode), or try local SMP agent with the deployed demo server:
`smp1.simplex.im:5223#pLdiGvm0jD1CMblnov6Edd/391OrYsShw+RgdfR0ChA=`
@@ -78,21 +78,6 @@ Deployment on [Linode](https://www.linode.com/) is performed via StackScripts, w
Please submit an [issue](https://github.com/simplex-chat/simplexmq/issues) if any problems occur.
-[
](TODO)
-
-## Deploy SMP server on DigitalOcean
-
-[DigitalOcean](https://cloud.digitalocean.com) operates on the concept of Droplets. Droplet is a unit of deployment instantiated based on a Snapshot. You can deploy SMP server using provided [Snapshot](TODO):
-
-- Create a DigitalOcean account or login with an already existing one.
-- [Create Droplet](https://cloud.digitalocean.com/droplets/new?size=s-1vcpu-1gb®ion=fra1).
-- Choose the region and plan according to your requirements (cheapest Regular plan should be sufficient).
-- Provide [ssh key](https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys-2) and confirm Droplet creation.
-- Ssh to created Droplet (`ssh root@`) to get SMP server public key hash - either from the welcome message or from `/etc/opt/simplex/pub_key_hash`. DigitalOcean has a good guide on [how to login to Droplet via ssh](https://docs.digitalocean.com/products/droplets/how-to/connect-with-ssh/).
-- Great, your own SMP server is ready! Use `ip_address#hash` as SMP server address in the client.
-
-Please submit an [issue](https://github.com/simplex-chat/simplexmq/issues) if any problems occur.
-
## SMP server design

diff --git a/img/digitalocean.png b/img/digitalocean.png
new file mode 100644
index 0000000000000000000000000000000000000000..1eada09c710e653de0e72f4908ab304cf53d67ec
GIT binary patch
literal 2569
zcmX|Dc{mhWA0Ej%_N{wuBeEo8Nm2HF%{HVAWzQIf5h_atkv;Bpi>^DvsUzib2ZyIh^r@HUhJd=W$sXkD>d*jt5UZc9Z)3x#S+==
zKku%G8XNOyN-c~obVH7!9#9_ZjW#ynqpu^;0a3cMP5y4*M`DU%j#aUX6wwWVP9i#D>*Jje7HFt-}PrjyQ
z%mmy%kpx{#Ix=3V7NJSkuz-BP5^U%FG&7pNqxgv)=oH>=_m_y>+l;{A
zaJ(h6Bt{Ps7~R?0gqhJFW{cg$CQ3p#|H>{m>u?Szo93o6ZDhLAzP!o}>MeC6#Mq>O0{t*~NI?;GrG7GJ$qJft%+vpz?mk<*ZA<5P;U=ghq
z9sre$;R!}eO!;hDiL;Pf;ML}?D3rx?)4E9+_eD{J@UCj5`iPF1pbJSc@gpif9@3E#HIBs!%OAF-q($66As+Ef26
zvp>J?#Y-y$=F4-8OnI9S`Ov
z-fG!)gmDpMVJ)<4X}L7!7xCC>J<$iN#r@67IekT4QKWud#!R7VS`myNGdHN5Us4!=
z!SD>g(ZbMO{P<~f0r|Xb|6KaX-IdA|>gWS7(xGgN8#V+I!s4wb8sRz;6WUnK8~KYN
zQ)vc5*0h>DLdY*vi+9&lULfR%@}OT@_!VwY9$98Iof8#k-K!pa?k~_LHl-7wvT=J#
zR;7D&{K|#+^D@4zajz_-BQt0`6N5u{0GQ0)E3Zq!u*s`zrRw?e;?)mCP>1G_nSQ5qiF47|6zCc5+OVy(4@0?1neSv?+Xe&Ml!(q*)ybB+iFu3i+5b;EVaP`6ZJeW1Pd8fzjiQyUp3+352`6S#kcb
znub?z?0uI_u3DCBsuFW5t=^k_4fBiNC=6HEp6s)SmALML7%h@3jd#}7K>49ONc-<&}jvd3z>S(mal*njmgd|&@JnH>@0SF)IkfCnF)
zA{i^CgH53fM^_wdW={ECKUQqdjgvL*7}usM_Ztu|MH@#foSXBCeD5e{wU9{YmS3)b
z(Gz2xLC~>a-u&b>3+Fc@$2=-C|NqgEgebQJ&{`Zc0zM7jB?gLgvH9;1I}rPjCSpCR4O
zb>C7{+k#(E7!i)xql)3Ow8U`INk%XphZ^eR)hh7JFduZ(hNOs%q*snnv$Q2|vtX}n
zUZ*I6C5eYuO)hIzlhz$)f%BioNkL10KD)Nvh9(uQVCOfl)9*d}Ppc6LjaOjvGI!Rp
zTeI1Q+U278-xbph$@CJG)Pc6Lt>TdNi-R=WY@@&!m0lyKFf*Z{97uboLG3ywXmB*?J
z4pyJ_b1%7FM1kp7A#;j9y!A42Tfz}Ta{*n&Jkm~08*pu^v3yg
z?W7N(!!jLzbNNJnl1Z>K%yh)2H0WCyi@I~^2C>iTBUKJ
ztxFBFC&Sh#AmX9fqSn(-6zjSvE91E>f4)%g{tKYGjxdf*-1U5R>MI3B=z@KxpV+@=
z;PIvnQp4)~JykAy2bd;JHJ@VB@|yK48%EQ07~ygw#gltHG2qyM`J`lWC8fcYHFU^5
YQ6Sjn^Q5Mq^XCCL+Pc~_S_P#47b!dVod5s;
literal 0
HcmV?d00001
diff --git a/img/digitalocean.svg b/img/digitalocean.svg
deleted file mode 100644
index 30404ce4c..000000000
--- a/img/digitalocean.svg
+++ /dev/null
@@ -1 +0,0 @@
-TODO
\ No newline at end of file
From 9f945492ddf985e18c23dceab2496e458012e65c Mon Sep 17 00:00:00 2001
From: Efim Poberezkin <8711996+efim-poberezkin@users.noreply.github.com>
Date: Fri, 9 Jul 2021 04:27:07 +1000
Subject: [PATCH 2/5] fix markdown error in crypto rfc (#167)
---
rfcs/2021-01-26-crypto.md | 8 ++++----
1 file changed, 4 insertions(+), 4 deletions(-)
diff --git a/rfcs/2021-01-26-crypto.md b/rfcs/2021-01-26-crypto.md
index 6e397da18..39ca6eb70 100644
--- a/rfcs/2021-01-26-crypto.md
+++ b/rfcs/2021-01-26-crypto.md
@@ -145,9 +145,9 @@ For each message, the agent performs the following actions to encrypt it:
3. Encrypt the message using this AES256 key with [AES-GCM-SIV](https://hackage.haskell.org/package/cryptonite-0.28/docs/Crypto-Cipher-AESGCMSIV.html) (AEAD scheme) using the function `encrypt` with a random nonce.
4. Encrypt the AES256 key with public encryption key for the queue using RSA-OAEP [encrypt](https://hackage.haskell.org/package/cryptonite-0.28/docs/Crypto-PubKey-RSA-OAEP.html#v:encrypt) function parameterized with [SHA256](https://hackage.haskell.org/package/cryptonite-0.28/docs/Crypto-Hash-Algorithms.html#t:SHA256) algorithm.
5. The message to send is concatenation of:
- 1. encrypted AES256 key,
- 2. AuthTag from encryption in step 3,
- 3. encrypted message (in this order)
+ 1. encrypted AES256 key,
+ 2. AuthTag from encryption in step 3,
+ 3. encrypted message (in this order).
As there is no additional data that is sent e2e in clear text, we potentially need some simpler algorithm, possibly the one implemented in the tutorial, that implements authenticated encryption without additional (unencrypted) data.
@@ -155,7 +155,7 @@ Or we could use this algorithm to allow some data that is sent e2e in clear text
### Message decryption
-Agent decrypt the message following the same steps in the opposite order
+Agent decrypts the message following the same steps in the opposite order:
1. Split encrypted message to AES256 key, AuthTag and encrypted message - tag and key have fixed size (?).
2. Decrypt AES256 key using the decryption key (the private key that recipient has).
From 65782d7ef6830cc4cf5d4039550d27b0b8f86dd9 Mon Sep 17 00:00:00 2001
From: Nikita Poberezkin <39944650+npoberezkin@users.noreply.github.com>
Date: Mon, 12 Jul 2021 19:22:35 +0300
Subject: [PATCH 3/5] add digital ocean deployment instruction (#168)
* add digital ocean deployment instruction
* fix instruction
* fix image link and remove ssh instruction link
---
README.md | 15 +++++++++++++++
1 file changed, 15 insertions(+)
diff --git a/README.md b/README.md
index b00276e71..a0d4b9d3a 100644
--- a/README.md
+++ b/README.md
@@ -78,6 +78,21 @@ Deployment on [Linode](https://www.linode.com/) is performed via StackScripts, w
Please submit an [issue](https://github.com/simplex-chat/simplexmq/issues) if any problems occur.
+[
](https://marketplace.digitalocean.com/apps/simplex-server)
+
+## Deploy SMP server on DigitalOcean
+
+You can deploy SMP server using [SimpleX Server 1-click app](https://marketplace.digitalocean.com/apps/simplex-server) from DigitalOcean marketplace:
+
+- Create a DigitalOcean account or login with an already existing one.
+- Click 'Create SimpleX server Droplet' button.
+- Choose the region and plan according to your requirements (cheapest Regular plan should be sufficient).
+- Provide ssh key and confirm Droplet creation.
+- SSH to created Droplet (`ssh root@`) to get SMP server public key hash - either from the welcome message or from `/etc/opt/simplex/pub_key_hash`. DigitalOcean has a good guide on [how to login to Droplet via ssh](https://docs.digitalocean.com/products/droplets/how-to/connect-with-ssh/).
+- Great, your own SMP server is ready! Use `ip_address#hash` as SMP server address in the client.
+
+Please submit an [issue](https://github.com/simplex-chat/simplexmq/issues) if any problems occur.
+
## SMP server design

From 8ac4b7777761bf3195b7b7c82dbe381c60a53a5c Mon Sep 17 00:00:00 2001
From: Nikita Poberezkin <39944650+npoberezkin@users.noreply.github.com>
Date: Sun, 25 Jul 2021 22:29:47 +0300
Subject: [PATCH 4/5] create cfg dir before server initialization (#173)
---
apps/smp-server/Main.hs | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/apps/smp-server/Main.hs b/apps/smp-server/Main.hs
index c0802a66b..c29f4800e 100644
--- a/apps/smp-server/Main.hs
+++ b/apps/smp-server/Main.hs
@@ -109,6 +109,7 @@ printConfig ServerConfig {serverPrivateKey, storeLog} = do
initializeServer :: ServerOpts -> IO ServerConfig
initializeServer opts = do
+ createDirectoryIfMissing False cfgDir
ini <- createIni opts
pk <- createKey ini
storeLog <- openStoreLog opts ini
@@ -201,7 +202,6 @@ readKey IniOpts {serverKeyFile} = do
createKey :: IniOpts -> IO C.FullPrivateKey
createKey IniOpts {serverKeyFile} = do
- createDirectoryIfMissing True cfgDir
(_, pk) <- C.generateKeyPair newKeySize
S.writeKeyFile S.TraditionalFormat serverKeyFile [PrivKeyRSA $ C.rsaPrivateKey pk]
pure pk
From dd6a53b0d274845723f1a65fa7bf358b2cb94827 Mon Sep 17 00:00:00 2001
From: Evgeny Poberezkin <2769109+epoberezkin@users.noreply.github.com>
Date: Thu, 5 Aug 2021 19:47:22 +0100
Subject: [PATCH 5/5] funding.yml (#177)
---
.github/FUNDING.yml | 1 +
1 file changed, 1 insertion(+)
create mode 100644 .github/FUNDING.yml
diff --git a/.github/FUNDING.yml b/.github/FUNDING.yml
new file mode 100644
index 000000000..395480a7d
--- /dev/null
+++ b/.github/FUNDING.yml
@@ -0,0 +1 @@
+open_collective: simplex-chat