Sync SSH metadata over Iroh
This commit is contained in:
parent
e4b788fec2
commit
9887b47a40
7 changed files with 686 additions and 20 deletions
|
|
@ -80,8 +80,11 @@ SSH certificate flows use the same split. Nodes can request new OpenSSH
|
|||
certificates or renewals through geth metadata. A machine with the CA key or
|
||||
YubiKey can approve the request and run an explicit `ssh-keygen -s ...` command,
|
||||
then import the resulting certificate for distribution. Certificate and key
|
||||
revocations are stored as signed-list-ready records and will be replicated over
|
||||
Iroh in later phases.
|
||||
revocations are stored as signed-list-ready records. The bootstrap can pull
|
||||
certificate-flow metadata over Iroh with `geth ssh cert sync <node-id>` when the
|
||||
peer grants `ssh_cert.sync` on `resource:ssh:certs`, and revocation metadata with
|
||||
`geth ssh revocation sync <node-id>` when the peer grants `ssh_revocation.sync`
|
||||
on `resource:ssh:revocations`.
|
||||
|
||||
## Resource Model
|
||||
|
||||
|
|
@ -164,7 +167,8 @@ OpenSSH KRL; serial and key-ID KRL entries require a CA public key via
|
|||
exports and OpenSSH KRL specification source files. Binary OpenSSH KRL files are
|
||||
not enumerable through OpenSSH tooling, so geth treats binary import as
|
||||
unsupported and asks for JSONL or the spec source. Revocation lists are not yet
|
||||
replicated over Iroh.
|
||||
full CRDT-replicated resources, but the daemon can already pull cert-flow and
|
||||
revocation metadata from authorized peers over the protected Iroh control ALPN.
|
||||
|
||||
## Keychain, Auth, And Secrets
|
||||
|
||||
|
|
|
|||
Loading…
Reference in a new issue