Two kinds live in module_secret and they behaved identically, which is right for one of them. A made secret is the mesh's: when a node regenerates its sealing key the mesh makes another and nothing is lost, because nothing else ever knew the old one. An accepted secret is not. A broker account's password exists because the broker was told about it. Regenerating one puts 32 random bytes where a working credential was — and the machine applies it, reports success, and the program reading it fails to authenticate somewhere else entirely, with the mesh insisting the secret was delivered, which it was. The row now records where the value came from, and a rejoined machine asking for an accepted one is refused with the remedy named: issue it again. No amount of pushing produces a password the broker has never heard of. Found while making the builder a module, which is the first thing to hold one.
17 lines
1006 B
SQL
17 lines
1006 B
SQL
-- Where a module's own secret came from.
|
|
--
|
|
-- Two kinds live in this table and they behaved identically, which was wrong in one direction
|
|
-- only. A *made* secret is the mesh's: if the node regenerates its sealing key, the mesh makes
|
|
-- another and nothing is lost, because nothing else ever knew the old one.
|
|
--
|
|
-- An *accepted* secret is not the mesh's to invent. A broker account's password exists because
|
|
-- the broker was told about it; a licence key exists because somebody bought it. Regenerating one
|
|
-- produces 32 random bytes where a working credential used to be -- and the machine applies it,
|
|
-- reports success, and the program reading it fails to authenticate somewhere else entirely.
|
|
--
|
|
-- Everything already here was made by the mesh: accepting one is newer than this table, and the
|
|
-- only caller that accepts is the builder's broker account, which is issued per push.
|
|
|
|
alter table module_secret add column origin text not null default 'made'
|
|
check (origin in ('made', 'accepted'));
|