Shell: tls, ntp and netstat (#90) #92

Merged
twisla merged 2 commits from net-tools-2 into main 2026-10-08 01:00:43 +00:00
Owner

Finishes #90: the three commands left on its list.

Command Tells you
tls <host> [port] A secure connection's certificate: who it is for, who signed it, until when, its SHA-256, and whether this device trusts it, with the reason when it doesn't
ntp [server] A time server's clock against this device's, and the round trip
netstat What the device listens on, and what is connected
  • tls handshakes without checking, so a bad certificate can be looked at, then checks it against the device's own roots and the name asked for. It needs 70 KB free and says so if there isn't.
  • ntp with no server asks the first one in Settings.

Checked

  • 546 host tests pass (2 new: the NTP packet and the year 2036, the offset in words, certificate names, dates).
  • On the device: tls against a good server, a Gemini capsule (self-signed), an expired certificate, a wrong name and a port that isn't TLS; ntp with and without a server; netstat.

Not checked: tls with IRC connected, ntp against a wrong clock, netstat while sharing.

Docs: the Shell guide, the "When the network doesn't work" how-to (two more steps and a section on what the device offers), the README, the milestone notes and status line.

Closes #90.

🤖 Generated with Claude Code

https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT

Finishes #90: the three commands left on its list. | Command | Tells you | |---|---| | `tls <host> [port]` | A secure connection's certificate: who it is for, who signed it, until when, its SHA-256, and whether this device trusts it, with the reason when it doesn't | | `ntp [server]` | A time server's clock against this device's, and the round trip | | `netstat` | What the device listens on, and what is connected | - `tls` handshakes without checking, so a bad certificate can be looked at, then checks it against the device's own roots and the name asked for. It needs 70 KB free and says so if there isn't. - `ntp` with no server asks the first one in Settings. **Checked** - 546 host tests pass (2 new: the NTP packet and the year 2036, the offset in words, certificate names, dates). - On the device: `tls` against a good server, a Gemini capsule (self-signed), an expired certificate, a wrong name and a port that isn't TLS; `ntp` with and without a server; `netstat`. **Not checked:** `tls` with IRC connected, `ntp` against a wrong clock, `netstat` while sharing. **Docs:** the Shell guide, the "When the network doesn't work" how-to (two more steps and a section on what the device offers), the README, the milestone notes and status line. Closes #90. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla added 1 commit 2026-10-08 00:55:01 +00:00
Shell: tls, ntp and netstat (#90)
Site / build (pull_request) Successful in 10s
CI / build (pull_request) Successful in 1m49s
9808013fc0
The rest of the issue's list. tls makes a handshake that checks nothing,
then says the certificate in words: who it is for, who signed it, until
when, and whether this device's roots and the name asked for accept it,
with the reason when they don't. ntp compares a time server's clock with
the device's. netstat lists what listens and what is connected.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla added 1 commit 2026-10-08 00:58:44 +00:00
N1: tls, ntp and netstat ship as v0.21.0
Site / build (pull_request) Successful in 9s
CI / build (pull_request) Successful in 1m32s
298407b5cf
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EhqxQ49eCju4CzKYNjZzwT
twisla merged commit 0498916740 into main 2026-10-08 01:00:43 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: twisla/roro9stack#92