A provider with one credential shares it with every consumer, remade for all at once (hq ADR 0158)
An offer may say `"credential": {"own": "<secret>"}`: the provider's own secret is the credential
every consumer of that provision receives, in the shape of a pair credential. The vault keeps one
value, sealed to the provider, to every consumer that holds the provision and to the operator, all
under one generation stamp; a consumer binding later, or `secret rotate` on the provider's secret,
makes a fresh value and seals it to every holder in one act, and the rotate command sends every
holding machine together. An accepted value is sealed to the consumers of the moment and never
remade: a consumer binding after it is refused with the way out (ADR 0113). The named own secret
must say how it is taken (issue 180), so the provider's start applies the file.
A need carries the shared secret's name from either side of the machine boundary; the plan mints a
consumer's copy from the provider's value. Registered manifests keep their bytes.
This commit is contained in:
@@ -45,6 +45,26 @@ type Sealed struct {
|
||||
ProviderKey string
|
||||
}
|
||||
|
||||
// Fresh is a new secret value, the shape Make seals: for the one caller that must seal one value
|
||||
// to many holders at once (novox/hq ADR 0158) and discards it the same way.
|
||||
func Fresh() string {
|
||||
value := make([]byte, 30)
|
||||
if _, err := rand.Read(value); err != nil {
|
||||
panic("the system's random source failed: " + err.Error())
|
||||
}
|
||||
return base64.RawURLEncoding.EncodeToString(value)
|
||||
}
|
||||
|
||||
// Stamp is a random mark for one act of sealing a value to several holders: rows carrying the same
|
||||
// stamp were sealed from the same value, which the mesh cannot otherwise tell, holding no plaintext.
|
||||
func Stamp() string {
|
||||
mark := make([]byte, 16)
|
||||
if _, err := rand.Read(mark); err != nil {
|
||||
panic("the system's random source failed: " + err.Error())
|
||||
}
|
||||
return hex.EncodeToString(mark)
|
||||
}
|
||||
|
||||
// Make generates a secret and seals it to both ends, keeping no readable copy.
|
||||
//
|
||||
// The plaintext exists for the length of this call. Rotation is therefore generating a new one
|
||||
|
||||
Reference in New Issue
Block a user