split cert and key location and allow key lookup on tpm

This commit is contained in:
pascal
2026-09-22 17:04:50 +02:00
parent d04aef6f14
commit 7fbde60b7c
17 changed files with 604 additions and 139 deletions
+2 -2
View File
@@ -171,7 +171,7 @@ type EngineConfig struct {
MTU uint16
CertPKCS11 certproof.PKCS11Config
CertStore certproof.Config
// for debug bundle generation
ProfileConfig *profilemanager.Config
@@ -1298,7 +1298,7 @@ func (e *Engine) applyInfoFlags(info *system.Info) {
// certificates reachable on this device, signing each challenge nonce for our peer key.
func (e *Engine) attachCertificateProofs(info *system.Info, checks []*mgmProto.Checks) {
peerKey := e.config.WgPrivateKey.PublicKey()
info.CertificateProofs = certproof.CollectProofs(e.ctx, checks, peerKey[:], e.config.CertPKCS11)
info.CertificateProofs = certproof.CollectProofs(e.ctx, checks, peerKey[:], e.config.CertStore)
}
func (e *Engine) currentSystemInfo(ctx context.Context) *system.Info {