Read the PKCS#11 token PIN from NB_TPM_PIN instead of the profile config

This commit is contained in:
Viktor Liu
2026-10-01 08:16:40 +02:00
parent 0641f0d7bb
commit ab2f8972be
6 changed files with 30 additions and 18 deletions
+4 -7
View File
@@ -191,13 +191,10 @@ type Config struct {
// NB_CERT_STORE_DIR or /etc/netbird/certs; see client/internal/certproof/README.md.
CertStoreDir string
// CertPKCS11PIN is the user PIN of the PKCS#11 token, tpm2-pkcs11 for one, whose
// certificates answer certificate posture checks on Linux. Setting it enables the
// token store; see client/internal/certproof/README.md.
CertPKCS11PIN string
// CertPKCS11URI is the RFC 7512 URI selecting that token and its module. Empty means
// the first token the p11-kit proxy exposes.
// CertPKCS11URI is the RFC 7512 URI selecting the PKCS#11 token, tpm2-pkcs11 for one,
// and its module, whose certificates answer certificate posture checks on Linux.
// Empty means the first token the p11-kit proxy exposes. The token's user PIN comes
// from NB_TPM_PIN, never from this file; see client/internal/certproof/README.md.
CertPKCS11URI string
// LazyConnection is the MDM-managed lazy-connection override ("on"/"off"/"").