A provider with one credential shares it with every consumer, remade for all at once (hq ADR 0158)
An offer may say `"credential": {"own": "<secret>"}`: the provider's own secret is the credential
every consumer of that provision receives, in the shape of a pair credential. The vault keeps one
value, sealed to the provider, to every consumer that holds the provision and to the operator, all
under one generation stamp; a consumer binding later, or `secret rotate` on the provider's secret,
makes a fresh value and seals it to every holder in one act, and the rotate command sends every
holding machine together. An accepted value is sealed to the consumers of the moment and never
remade: a consumer binding after it is refused with the way out (ADR 0113). The named own secret
must say how it is taken (issue 180), so the provider's start applies the file.
A need carries the shared secret's name from either side of the machine boundary; the plan mints a
consumer's copy from the provider's value. Registered manifests keep their bytes.
This commit is contained in:
+8
@@ -0,0 +1,8 @@
|
||||
-- A provider with one credential shares it with every consumer (novox/hq ADR 0158).
|
||||
--
|
||||
-- The provider's own secret and every consumer's pair row then carry one value, sealed once per
|
||||
-- holder. The mesh keeps no plaintext, so it cannot tell by reading that they agree; it stamps the
|
||||
-- act that made them instead. A pair row whose stamp is the own secret's was sealed from the same
|
||||
-- value; one whose stamp differs, or is missing, is remade for every holder at once.
|
||||
alter table module_secret add column generation text;
|
||||
alter table secret add column generation text;
|
||||
Reference in New Issue
Block a user