pki

package
v1.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: Apache-2.0 Imports: 16 Imported by: 0

Documentation

Overview

Package pki is the server's built-in certificate authority for workers.

The CA key is derived from the server's master key, so every replica of a server has the same CA without storing or sharing anything, and the CA certificate is byte-identical everywhere (Ed25519 signatures are deterministic and every field is fixed).

A worker enrolls by proving it knows the join token without sending it: both sides compute an HMAC keyed by the token over keying material exported from their TLS session, so a proof made for one connection is useless on another and a machine in the middle, holding two different sessions, can neither pass nor relay it. The server answers with a certificate for the worker's own public key and the CA certificate, both covered by the server's HMAC, which is how the worker learns to trust the CA. From then on each side verifies the other's certificate: the server presents a certificate valid only for server authentication, workers present certificates valid only for client authentication, so a worker's certificate can never impersonate the server.

Index

Constants

View Source
const ExporterLabel = "EXPORTER-stampede-enroll"

ExporterLabel is the TLS exporter label enrollment proofs are bound to.

View Source
const Purpose = "stampede worker CA v1"

Purpose is the keyring derivation label for the CA key. Changing it changes the CA, invalidating every issued certificate.

View Source
const WorkerURIPrefix = "stampede://worker/"

WorkerURIPrefix starts the URI SAN that names a worker in its certificate.

Variables

This section is empty.

Functions

func Binding

func Binding(cs tls.ConnectionState) ([]byte, error)

Binding returns the keying material exported from a TLS session for enrollment proofs.

func EnrollTLS

func EnrollTLS(pin string) *tls.Config

EnrollTLS is the TLS configuration for enrolling: the worker does not know the CA yet, so it accepts any certificate here and checks the chain against the CA from the authenticated reply afterwards. When pin is set (a CA fingerprint), the chain must also lead to that CA.

func Equal

func Equal(a, b []byte) bool

Equal compares proofs in constant time.

func Fingerprint

func Fingerprint(der []byte) string

Fingerprint is "sha256:" and the hex SHA-256 of a DER certificate.

func PeerWorker

func PeerWorker(cs tls.ConnectionState) (*x509.Certificate, error)

PeerWorker returns the verified worker certificate of a connection, or an error when the peer presented none or one not for client use.

func ServerProof

func ServerProof(token string, binding, cert, caDER []byte) []byte

ServerProof is the server's proof that it knows the join token and that cert and caDER come from it.

func VerifyServer

func VerifyServer(caDER []byte) func(rawCerts [][]byte, _ [][]*x509.Certificate) error

VerifyServer checks a server's certificate chain against caDER and requires server-authentication usage. It does not check a host name: the CA is private to one server and issues no other server certificates.

func WorkerCert

func WorkerCert(key ed25519.PrivateKey, certDER, caDER []byte) (tls.Certificate, *x509.Certificate, error)

WorkerCert assembles a worker's tls.Certificate from its key and the issued certificate, after checking that the certificate is for that key and chains to caDER for client authentication.

func WorkerProof

func WorkerProof(token string, binding []byte, name string, pub ed25519.PublicKey) []byte

WorkerProof is the worker's proof that it knows the join token.

func WorkerTLS

func WorkerTLS(caDER []byte, cert tls.Certificate) *tls.Config

WorkerTLS is a worker's TLS configuration once it holds a certificate.

Types

type CA

type CA struct {
	Cert *x509.Certificate
	DER  []byte
	// contains filtered or unexported fields
}

CA is a certificate authority with an Ed25519 key.

func NewCA

func NewCA(seed []byte) (*CA, error)

NewCA builds the CA from a 32-byte seed (from keyring.Derive(Purpose, 32)).

func (*CA) IssueWorker

func (ca *CA) IssueWorker(name, id string, pub ed25519.PublicKey, validity time.Duration) ([]byte, error)

IssueWorker issues a client certificate for a worker's Ed25519 public key.

func (*CA) Pool

func (ca *CA) Pool() *x509.CertPool

Pool is a pool holding only the CA.

func (*CA) ServerCert

func (ca *CA) ServerCert(hosts []string, validity time.Duration) (tls.Certificate, error)

ServerCert issues a certificate for the worker port, valid for server authentication only. Workers check it against the CA and the usage, not against a host name, so hosts are informational.

func (*CA) ServerTLS

func (ca *CA) ServerTLS(cert tls.Certificate) *tls.Config

ServerTLS is the worker port's TLS configuration: TLS 1.3 (enrollment proofs need exported keying material), the CA-issued server certificate, and client certificates verified when given. The coordinator decides whether a connection needs one (the Connect stream does, Enroll does not).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL