server: enroll against fmr.echo-lot.app; mint links from the CLI
The control plane now advertises the same name the web UI answers on. That is safe because the client authenticates by SPKI pin and explicitly does not verify the hostname — "pin is the trust, not the name" — so no certificate covers or needs to cover either name. The per-host name still means something, though, and the rule it encodes has to survive: pinning binds a client to one server's key, so fmr may be a CNAME to exactly one host and never a multi-address service record. A second server gets enrolled as fmr-2 explicitly, because a client that reaches a different key does not fail over, it fails. Minting a link was broken and had been since the authenticated admin UI replaced the old admin API: enroll-link.sh still posted to 127.0.0.1:8444/admin/enroll-tokens, an endpoint that no longer exists on a listener that no longer binds loopback. Rather than add a second unauthenticated door — which is how the old one ended up briefly reachable from the network — the binary mints its own link. Whoever can run it against the state directory already holds every privilege the server has, so authenticating them to themselves would be theatre. EnrollmentURI is shared with the running server's EnrollmentLink rather than reimplemented. Two copies of that encoding would eventually disagree, and the failure mode is a pin that looks right and surfaces as an inscrutable TLS error rather than as a bad pin. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
8001234e8b
commit
e0428b4c84
@@ -825,10 +825,16 @@ func maxOrEmpty(r compat.Range) string {
|
||||
// three parts at once — its own URL, its own SPKI pin, and the token. An operator copying a pin
|
||||
// by hand is the step that goes wrong, and a pin wrong by one character does not fail loudly.
|
||||
func (s *Server) EnrollmentLink(token string) string {
|
||||
u := s.PublicControlURL
|
||||
return EnrollmentURI(s.PublicControlURL, s.PinB64, token)
|
||||
}
|
||||
|
||||
// EnrollmentURI is the same assembly without a running server, for the mint-a-link CLI action.
|
||||
// Shared rather than reimplemented: two copies of this encoding would eventually disagree, and
|
||||
// the failure mode is a pin that looks right and produces an inscrutable TLS error.
|
||||
func EnrollmentURI(publicURL, pinB64, token string) string {
|
||||
return "echolot://enroll?v=1" +
|
||||
"&u=" + url.QueryEscape(strings.TrimRight(u, "/")) +
|
||||
"&p=" + url.QueryEscape("pin-sha256:"+s.PinB64) +
|
||||
"&u=" + url.QueryEscape(strings.TrimRight(publicURL, "/")) +
|
||||
"&p=" + url.QueryEscape("pin-sha256:"+pinB64) +
|
||||
"&t=" + url.QueryEscape(token)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user