A node generates the key it serves TLS with
A fourth key, reported at enrolment like the others. The reasoning is the one this file's neighbours already give twice: a key used for two purposes is one rotation away from breaking the other. The private half never leaves the machine. The mesh is told the public half and signs a certificate binding it to this node's name inside the mesh — so there is nothing to seal, and a copy of what the mesh holds certifies nothing it did not already certify. It does not make one on demand, for the same reason the sealing key does not: a key the mesh has never certified is a key nothing will trust, so a node that quietly generated one would serve a certificate for a key it no longer has and fail in a way that names neither.
This commit is contained in:
@@ -37,6 +37,10 @@ func TestWhatThisNodeSaysWhenItJoins(t *testing.T) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
serving, err := identity.GenerateServingKey()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
request := EnrolRequest{
|
||||
Node: "workstation",
|
||||
@@ -44,6 +48,7 @@ func TestWhatThisNodeSaysWhenItJoins(t *testing.T) {
|
||||
PublicKey: mine.Public,
|
||||
OverlayKey: overlay.Public,
|
||||
SealingKey: sealing.Public,
|
||||
ServingKey: serving.Public,
|
||||
Profile: map[string]any{"seat": true},
|
||||
}
|
||||
body, err := json.MarshalIndent(request, "", " ")
|
||||
|
||||
Reference in New Issue
Block a user