An enrolling node asks again while the mesh cannot answer, and proves it holds its key (issue 083) #19
@@ -111,7 +111,7 @@ func Enrol(ctx context.Context, o Options, sys system.System, control controlPla
|
||||
if err != nil {
|
||||
return out, fmt.Errorf(
|
||||
"%s would not enrol this machine: %w\n%s\n"+
|
||||
"The token is one-time and has now been spent; running this again issues "+
|
||||
"The token is one-time and may have been spent; running this again issues "+
|
||||
"another, so a re-run is safe", o.Host, err, indent(strings.TrimSpace(joined)))
|
||||
}
|
||||
if !strings.Contains(joined, "enrolled as "+o.Node) {
|
||||
|
||||
@@ -94,8 +94,11 @@ func answered(reply EnrolReply, asking time.Duration) (again bool, err error) {
|
||||
case reply.TryAgain && asking < EnrolPatience:
|
||||
return true, nil
|
||||
case reply.TryAgain:
|
||||
return false, fmt.Errorf("%w for %s: %s. The token was not spent — run enrol again with it",
|
||||
ErrNotNow, EnrolPatience, reply.Refusal)
|
||||
// Said with what to do. The mesh holds the token for this attempt's keys for as long as
|
||||
// this node kept asking, so a new attempt — with keys of its own — waits that out first.
|
||||
return false, fmt.Errorf("%w for %s: %s. The token was not spent: wait about %s and run "+
|
||||
"enrol again with it; if it is then refused, issue a new one",
|
||||
ErrNotNow, EnrolPatience, reply.Refusal, EnrolPatience)
|
||||
default:
|
||||
return false, fmt.Errorf("%w: %s", ErrRefused, reply.Refusal)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user