A node generates the key it serves TLS with
A fourth key, reported at enrolment like the others. The reasoning is the one this file's neighbours already give twice: a key used for two purposes is one rotation away from breaking the other. The private half never leaves the machine. The mesh is told the public half and signs a certificate binding it to this node's name inside the mesh — so there is nothing to seal, and a copy of what the mesh holds certifies nothing it did not already certify. It does not make one on demand, for the same reason the sealing key does not: a key the mesh has never certified is a key nothing will trust, so a node that quietly generated one would serve a certificate for a key it no longer has and fail in a way that names neither.
This commit is contained in:
+13
-1
@@ -472,6 +472,15 @@ func enrol(ctx context.Context, opts options) error {
|
||||
}
|
||||
fmt.Printf("generated this node's sealing key: %s\n", sealing.Public)
|
||||
|
||||
// And the key it serves TLS with on its name inside the mesh. Generated here for the same
|
||||
// reason as the others: the private half must never have been anywhere else, and the mesh
|
||||
// only ever certifies the public one.
|
||||
serving, err := identity.GenerateServingKey()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
fmt.Printf("generated this node's serving key: %s\n", serving.Public)
|
||||
|
||||
// What this machine can be asked to do, gathered before joining rather than after. The
|
||||
// control plane cannot decide what a node should run without it, so it travels with the
|
||||
// request instead of being asked for in a second round trip.
|
||||
@@ -482,7 +491,7 @@ func enrol(ctx context.Context, opts options) error {
|
||||
}
|
||||
|
||||
reply, err := link.Enrol(ctx, token.Broker, token.Fingerprint, *name, token.Secret,
|
||||
mine.Public, mine.Overlay.Public, sealing.Public, reported, opts.timeout)
|
||||
mine.Public, mine.Overlay.Public, sealing.Public, serving.Public, reported, opts.timeout)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -531,6 +540,9 @@ func enrol(ctx context.Context, opts options) error {
|
||||
[]byte(sealing.Private+"\n"), 0o600); err != nil {
|
||||
return fmt.Errorf("cannot write this node's sealing key: %w", err)
|
||||
}
|
||||
if err := identity.WriteServingKey(identity.ServingKeyPath(opts.state), serving); err != nil {
|
||||
return fmt.Errorf("cannot write this node's serving key: %w", err)
|
||||
}
|
||||
|
||||
fmt.Printf("\nenrolled as %s\n", reply.Node)
|
||||
fmt.Printf(" identity %s\n", identityPath)
|
||||
|
||||
Reference in New Issue
Block a user