A node generates its own key for the private network

Curve25519, which is what WireGuard uses. The private half never leaves the
machine and is written to a file of its own, so the interface configuration the
mesh composes can point at it without ever carrying it.

Separate from the identity keypair on purpose. One signs messages to the mesh
and the other encrypts traffic between nodes -- different things verified by
different parties at different times, and a key used for two purposes is one
rotation away from breaking the other.
This commit is contained in:
2026-08-29 16:58:58 +02:00
parent 38d7b2d8af
commit 732905a6a6
2 changed files with 61 additions and 0 deletions
+7
View File
@@ -28,6 +28,9 @@ func Path(statePath string) string {
return filepath.Join(filepath.Dir(statePath), FileName)
}
// dirOf is where a node keeps everything it knows about itself.
func dirOf(statePath string) string { return filepath.Dir(statePath) }
// Identity is this node's own keypair, the name the mesh knows it by, and what it needs to get
// back to that mesh without a person.
//
@@ -44,6 +47,10 @@ type Identity struct {
Private []byte `json:"private"`
Membership Membership `json:"membership"`
// Overlay is this node's key on the private network. Generated here, like the identity above,
// and for the same reason: the mesh computes a graph it cannot impersonate.
Overlay OverlayKey `json:"overlay"`
}
// Membership is how this node reaches the mesh it belongs to, and who it believes.