A token can be issued for a machine's tunnel key, and it joins through the tunnel
token issue --overlay-key records the key the machine made, binds the token to it, gives the machine its address and makes it a peer of the hub, pushing the hub before the token is shown. The token carries the hub's tunnel and the bus at its holder's address on the private network, and enrolment refuses any other key (novox/hq ADR 0169). The bus is no longer public, so a machine outside the mesh can join only this way; a token without a key is still what the machine running the bus joins its own mesh with. Also a token verb, which says it replaces running the command by hand and adding a peer to the hub with wg.
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
-- A token issued for a tunnel key (novox/hq ADR 0169).
|
||||
--
|
||||
-- A machine that joins through the tunnel makes its key first, and the token is issued for it: the
|
||||
-- hub is told the key before the token is shown. So enrolment must take that key and no other — a
|
||||
-- different one is a machine the hub does not know, offering a tunnel that would never answer. Null
|
||||
-- for a token issued without one, which enrols as before.
|
||||
alter table enrolment_token add column overlay_key text;
|
||||
Reference in New Issue
Block a user