docs: clarify Signal message encryption and Windows PATH after install (#979)

* docs: clarify Signal message encryption and Windows PATH after install

- how-netbird-works: the Signal candidate message uses NaCl box
  (Curve25519, XSalsa20, Poly1305): a shared key derived from the
  local private key and the remote public key, no separate signature.
  Spell that out so readers with an RSA sign-then-encrypt model do not
  read the sentence as a mistake.
- windows install: both installers add C:\Program Files\NetBird to the
  system PATH, but terminals opened before the install keep the old
  PATH. Add a note to open a new terminal, and use the full exe path in
  the scripted install + setup-key snippets, where the same shell runs
  both commands.

* docs: state that Signal sees the peers' public keys, not the body

* docs: keep bare netbird up in the setup-key snippets, note a new terminal instead

* docs: drop the repeated new-terminal note from the setup-key section
This commit is contained in:
Jack Carter
2026-09-28 12:57:33 +02:00
committed by GitHub
parent 8eafcdc59e
commit 97f7ca40f9
2 changed files with 4 additions and 1 deletions
@@ -74,7 +74,7 @@ The client application requests a user to log in with an Identity Provider (IDP)
* **Receiving network updates from the Management service.**
Each peer receives initial configuration and a list of peers with corresponding public keys and IP addresses so that it can establish a point-to-point connection.
* **Establishing point-to-point WireGuard connection.** To establish a connection with a remote peer, the Client first discovers the most suitable connection candidate, or simply address (IP:port) that other peers can use to connect to it.
It then sends it to the remote peer via Signal. This message is encrypted with the peer's private key and a public key of the remote peer.
It then sends it to the remote peer via Signal. The message body is encrypted end to end with a shared key that each peer derives from its own private key and the other peer's public key (NaCl `box`: Curve25519, XSalsa20, Poly1305). Signal sees the two peers' public keys, so it knows who is talking to whom, but never the contents. The same shared key also authenticates the message, so there is no separate signature step.
The remote peer does the same and once the peers can reach each other, they establish an encrypted WireGuard tunnel.
* **Applying access control policies.** The client application applies access control rules that are received from the Management service.
The client uses a system's available firewall manager like `nftables` to apply the rules.
@@ -10,6 +10,9 @@ The NetBird client allows a peer to join a pre-existing NetBird deployment. If a
2. Execute the installer and proceed with the installation steps
3. This will install the UI client in the `C:\Program Files\NetBird` and add the daemon service
4. After installing, you can follow the steps from [Running NetBird with SSO Login](#running-net-bird-with-sso-login).
<Note>
Open a new terminal before running `netbird` commands. The installer adds `C:\Program Files\NetBird` to the system `PATH`, but terminals that were already open keep the old `PATH`.
</Note>
<Note>
To uninstall the client and service, you can use Add/Remove programs
</Note>