feat(namecoin): add electrumx2.testls.space LE-cert server to default list

Add electrumx2.testls.space:50012 to DEFAULT_ELECTRUMX_SERVERS and
TOR_ELECTRUMX_SERVERS as a redundancy endpoint for the testls.space
operator. It runs on the same box as relay.testls.bit (23.158.233.10)
but terminates TLS at nginx with a publicly-trusted Let's Encrypt cert
(CN=electrumx2.testls.space, issuer LE YE1) instead of the self-signed
relay.testls.bit cert on the standard ports.

usePinnedTrustStore is left at the default (false) since the system
trust store is sufficient, same as electrum.nmc.ethicnology.com.

The same nginx vhost also exposes WSS on port 50014, making it the
second browser-viable public Namecoin ElectrumX endpoint (alongside
electrum.nmc.ethicnology.com) for pure-browser Nostr clients that
cannot use self-signed certs.

(cherry picked from commit 645382a95b9a314eb6a4e1221ba97dfc1c13f1ae)

Applied from nostr proposal
c0eb8d1a09651c377827f4aa97c1ed7a2f93fafceb823233c5650506b661b8ba
(branch feat/electrumx2-le-server). Cherry-picked rather than merged via
`ngit pr merge` because that proposal is not surfaced by `ngit pr list` --
it is absent from all statuses and `ngit pr view` reports "proposal not
found", though the event is well formed on relay.ngit.dev with the correct
a-tag and r-tag. It appears to collide with a stale earlier proposal for the
same branch name.

Endpoint verified before applying:
- electrumx2.testls.space resolves to 23.158.233.10, the same host as the
  existing relay.testls.bit / 23.158.233.10 entries, as the commit claims.
- TLS on :50012 presents CN=electrumx2.testls.space issued by Let's Encrypt
  (C=US, O=Let's Encrypt, CN=YE1), so usePinnedTrustStore = false is correct.
- server.version reports ElectrumX 1.16.0 and server.features reports
  genesis_hash 000000000062b72c5e2ceb45fbc8587e807c155b0da735e6483dfba2f0a9c770,
  i.e. it indexes Namecoin rather than Bitcoin.

Note this is the third default entry pointing at host 23.158.233.10, so it
adds certificate-path redundancy (works where a self-signed cert is stripped)
rather than host redundancy. Low risk: nameShowWithFallback tries servers
sequentially and returns on first success, and this entry is appended last in
both lists.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GYVqQqpUY1xqYG5LUY6jQr
This commit is contained in:
mstrofnone
2026-08-31 15:38:19 -04:00
committed by Vitor Pamplona
co-authored by Claude Opus 5
parent 9ea7c36cf9
commit 6cf09f0d75
@@ -122,6 +122,21 @@ val DEFAULT_ELECTRUMX_SERVERS =
// self-signed peer above is unreachable (e.g. corporate networks that
// strip unknown CAs but allow LE).
ElectrumxServer("electrum.nmc.ethicnology.com", 50002, useSsl = true, usePinnedTrustStore = false),
// electrumx2.testls.space — redundancy endpoint for the testls.space
// operator, on the same box as relay.testls.bit (23.158.233.10) but
// terminating TLS at nginx with a publicly-trusted Let's Encrypt cert
// (CN=electrumx2.testls.space, issuer LE YE1) instead of the self-signed
// relay.testls.bit cert served on the standard ports. usePinnedTrustStore
// is left at the default (false) because the system trust store is
// sufficient.
//
// Port 50012 is the TCP+TLS endpoint (what this client uses). The same
// nginx vhost also exposes WSS on port 50014 for browser-based Nostr
// clients that want to do Namecoin NIP-05 lookups without a backend
// proxy — browsers refuse WSS to self-signed certs, so the LE cert on
// electrumx2 makes it the first browser-viable public Namecoin
// ElectrumX endpoint alongside electrum.nmc.ethicnology.com.
ElectrumxServer("electrumx2.testls.space", 50012, useSsl = true, usePinnedTrustStore = false),
// Note: no bare-IP companion entry for electrum.nmc.ethicnology.com.
// Unlike the 46.229.238.187 / 23.158.233.10 peers above (which use
// usePinnedTrustStore=true and DER-SHA256 pinning that doesn't care
@@ -157,4 +172,6 @@ val TOR_ELECTRUMX_SERVERS =
ElectrumxServer("23.158.233.10", 50002, useSsl = true, usePinnedTrustStore = true),
// electrum.nmc.ethicnology.com — public LE-cert ElectrumX. See clearnet list above.
ElectrumxServer("electrum.nmc.ethicnology.com", 50002, useSsl = true, usePinnedTrustStore = false),
// electrumx2.testls.space — LE-cert redundancy endpoint. See clearnet list above.
ElectrumxServer("electrumx2.testls.space", 50012, useSsl = true, usePinnedTrustStore = false),
)