An enrolling node signs its request with the identity it just generated, so the mesh can tell it from anyone who knows its public key (novox/hq issue 083)

This commit is contained in:
2026-09-22 14:33:31 +02:00
parent eaebae7b36
commit 406a5559b0
3 changed files with 34 additions and 3 deletions
+5 -1
View File
@@ -493,8 +493,12 @@ func enrol(ctx context.Context, opts options) error {
_ = json.Unmarshal(raw, &reported)
}
// Signed with the identity just generated, so the mesh can tell this machine from anyone else
// who knows its public key (novox/hq issue 083).
proof := mine.Sign(link.EnrolProof(token.Secret, mine.Public, mine.Overlay.Public,
sealing.Public, serving.Public))
reply, err := link.Enrol(ctx, token.Broker, token.Fingerprint, *name, token.Secret,
mine.Public, mine.Overlay.Public, sealing.Public, serving.Public, reported, opts.timeout)
mine.Public, mine.Overlay.Public, sealing.Public, serving.Public, reported, proof, opts.timeout)
if err != nil {
return err
}