Add manual signed peer card exchange

This commit is contained in:
Eric Wendland 2026-05-18 04:03:52 +02:00
commit 1ab24631cd
14 changed files with 360 additions and 25 deletions

View file

@ -42,14 +42,15 @@ and candidate-discovery mechanisms only. They do not grant trust, mutate
authorization state, or make EndpointID knowledge sufficient for access.
The current daemon can enable Iroh's local-network discovery service through
`[iroh].local_discovery = true`, which is the default. This publishes and
discovers Iroh node addressing. Signed geth peer-card payloads over LAN
discovery remain separate future work.
discovers Iroh node addressing. `geth peer export/import/list` supports manual
exchange of signed peer cards as untrusted candidates. Automatic signed
peer-card advertisement over LAN discovery remains separate future work.
Peer cards are the discovery payload. A peer card carries node ID, agent ID,
endpoint candidates, timestamp, and signature metadata. The current scaffold
stores peer cards as untrusted metadata in `peer_cards`; signature verification
and trust reduction are future work. `auth explain` reports when a subject is
only a discovered peer candidate and denies access.
endpoint candidates, timestamp, signing public key, and an Ed25519 signature
over a canonical payload. Imported peer cards are stored as untrusted metadata
in `peer_cards`; trust reduction is future work. `auth explain` reports when a
subject is only a discovered peer candidate and denies access.
The daemon starts this endpoint during `geth daemon run` and keeps it alive for
the daemon lifetime. When endpoint startup succeeds, the Iroh EndpointID is