From 6cf09f0d75b07037a7d9af56412e47404d6f865d Mon Sep 17 00:00:00 2001 From: mstrofnone Date: Sat, 22 Aug 2026 06:46:18 +1000 Subject: [PATCH] feat(namecoin): add electrumx2.testls.space LE-cert server to default list Add electrumx2.testls.space:50012 to DEFAULT_ELECTRUMX_SERVERS and TOR_ELECTRUMX_SERVERS as a redundancy endpoint for the testls.space operator. It runs on the same box as relay.testls.bit (23.158.233.10) but terminates TLS at nginx with a publicly-trusted Let's Encrypt cert (CN=electrumx2.testls.space, issuer LE YE1) instead of the self-signed relay.testls.bit cert on the standard ports. usePinnedTrustStore is left at the default (false) since the system trust store is sufficient, same as electrum.nmc.ethicnology.com. The same nginx vhost also exposes WSS on port 50014, making it the second browser-viable public Namecoin ElectrumX endpoint (alongside electrum.nmc.ethicnology.com) for pure-browser Nostr clients that cannot use self-signed certs. (cherry picked from commit 645382a95b9a314eb6a4e1221ba97dfc1c13f1ae) Applied from nostr proposal c0eb8d1a09651c377827f4aa97c1ed7a2f93fafceb823233c5650506b661b8ba (branch feat/electrumx2-le-server). Cherry-picked rather than merged via `ngit pr merge` because that proposal is not surfaced by `ngit pr list` -- it is absent from all statuses and `ngit pr view` reports "proposal not found", though the event is well formed on relay.ngit.dev with the correct a-tag and r-tag. It appears to collide with a stale earlier proposal for the same branch name. Endpoint verified before applying: - electrumx2.testls.space resolves to 23.158.233.10, the same host as the existing relay.testls.bit / 23.158.233.10 entries, as the commit claims. - TLS on :50012 presents CN=electrumx2.testls.space issued by Let's Encrypt (C=US, O=Let's Encrypt, CN=YE1), so usePinnedTrustStore = false is correct. - server.version reports ElectrumX 1.16.0 and server.features reports genesis_hash 000000000062b72c5e2ceb45fbc8587e807c155b0da735e6483dfba2f0a9c770, i.e. it indexes Namecoin rather than Bitcoin. Note this is the third default entry pointing at host 23.158.233.10, so it adds certificate-path redundancy (works where a self-signed cert is stripped) rather than host redundancy. Low risk: nameShowWithFallback tries servers sequentially and returns on first success, and this entry is appended last in both lists. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01GYVqQqpUY1xqYG5LUY6jQr --- .../namecoin/ElectrumXServer.kt | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/quartz/src/commonMain/kotlin/com/vitorpamplona/quartz/nip05DnsIdentifiers/namecoin/ElectrumXServer.kt b/quartz/src/commonMain/kotlin/com/vitorpamplona/quartz/nip05DnsIdentifiers/namecoin/ElectrumXServer.kt index 992b55328d..6076d358ff 100644 --- a/quartz/src/commonMain/kotlin/com/vitorpamplona/quartz/nip05DnsIdentifiers/namecoin/ElectrumXServer.kt +++ b/quartz/src/commonMain/kotlin/com/vitorpamplona/quartz/nip05DnsIdentifiers/namecoin/ElectrumXServer.kt @@ -122,6 +122,21 @@ val DEFAULT_ELECTRUMX_SERVERS = // self-signed peer above is unreachable (e.g. corporate networks that // strip unknown CAs but allow LE). ElectrumxServer("electrum.nmc.ethicnology.com", 50002, useSsl = true, usePinnedTrustStore = false), + // electrumx2.testls.space — redundancy endpoint for the testls.space + // operator, on the same box as relay.testls.bit (23.158.233.10) but + // terminating TLS at nginx with a publicly-trusted Let's Encrypt cert + // (CN=electrumx2.testls.space, issuer LE YE1) instead of the self-signed + // relay.testls.bit cert served on the standard ports. usePinnedTrustStore + // is left at the default (false) because the system trust store is + // sufficient. + // + // Port 50012 is the TCP+TLS endpoint (what this client uses). The same + // nginx vhost also exposes WSS on port 50014 for browser-based Nostr + // clients that want to do Namecoin NIP-05 lookups without a backend + // proxy — browsers refuse WSS to self-signed certs, so the LE cert on + // electrumx2 makes it the first browser-viable public Namecoin + // ElectrumX endpoint alongside electrum.nmc.ethicnology.com. + ElectrumxServer("electrumx2.testls.space", 50012, useSsl = true, usePinnedTrustStore = false), // Note: no bare-IP companion entry for electrum.nmc.ethicnology.com. // Unlike the 46.229.238.187 / 23.158.233.10 peers above (which use // usePinnedTrustStore=true and DER-SHA256 pinning that doesn't care @@ -157,4 +172,6 @@ val TOR_ELECTRUMX_SERVERS = ElectrumxServer("23.158.233.10", 50002, useSsl = true, usePinnedTrustStore = true), // electrum.nmc.ethicnology.com — public LE-cert ElectrumX. See clearnet list above. ElectrumxServer("electrum.nmc.ethicnology.com", 50002, useSsl = true, usePinnedTrustStore = false), + // electrumx2.testls.space — LE-cert redundancy endpoint. See clearnet list above. + ElectrumxServer("electrumx2.testls.space", 50012, useSsl = true, usePinnedTrustStore = false), )