The mesh certifies names inside it
08-connectivity keeps two authorities apart on purpose: a public one for names the outside world reaches, and the mesh's own for names only the mesh knows. Nothing implemented the second, so anything between machines was plaintext or trust-on-first-use — which the design refuses everywhere else. A node now generates a fourth key at enrolment and reports the public half. A fourth, because a key used for two purposes is one rotation away from breaking the other: the identity key signs messages to the mesh and would do for TLS, and reusing it would mean rotating a node's identity every time its certificate is replaced. **Nothing secret travels and nothing is sealed.** A certificate authority says "this name belongs to the holder of this key", so the mesh signs a public half it cannot use, and the certificate it issues is public. A module asks for one and is given the certificate and, if it wants, the mesh's own — the private key is a path to a file the machine already has, the same arrangement the private network's key uses. Asserted by verifying rather than inspecting, because a certificate that parses and does not chain fails at the moment something connects: - what the mesh issues verifies against the mesh, for the name asked for - the name is in the subject alternative names, since a certificate carrying it only in the common name is refused by every modern client - it certifies the key the node generated and no other - another mesh's certificate does not verify, which is the whole point of two authorities being separate - the authority cannot sign another authority — one that could is one that can be delegated without anybody deciding to - two control planes starting together agree on one authority, or a mesh has certificates half its machines refuse Certificates last ten years, which is a choice: a short life needs something to renew it, and a renewal that fails silently is a mesh that stops trusting itself on a date nobody wrote down. What makes one replaceable is that the mesh reissues on demand, not that it expires.
This commit is contained in:
@@ -50,6 +50,11 @@ type EnrolRequest struct {
|
||||
// something nothing else can read, and it must never be able to read it either.
|
||||
SealingKey string `json:"sealing_key,omitempty"`
|
||||
|
||||
// ServingKey is the public half of the key this node serves TLS with on its internal name.
|
||||
// The mesh signs a certificate binding it; the private half never leaves the machine, so
|
||||
// there is nothing to seal and a copy of what the mesh holds certifies nothing new.
|
||||
ServingKey string `json:"serving_key,omitempty"`
|
||||
|
||||
// Profile is what this machine can be asked to do. The control plane cannot decide what a
|
||||
// node should run without it, so it arrives with enrolment rather than being asked for after.
|
||||
Profile map[string]any `json:"profile,omitempty"`
|
||||
|
||||
Reference in New Issue
Block a user