mirror of
https://github.com/netbirdio/netbird.git
synced 2026-10-06 13:39:07 +02:00
[client] persist Rosenpass static keypair across restarts
The Rosenpass static keypair was regenerated on every engine start (rp.GenerateKeyPair in NewManager), so the local ~512KB public key — and its fingerprint — changed on each client restart. Persist the keypair to <StateDir>/rosenpass_key.json with 0600 permissions (same protection tier as the WireGuard private key), and reload it on start so the public key stays stable across restarts. A missing, corrupt, or version-incompatible file degrades gracefully to generating a fresh ephemeral keypair (previous behaviour); an empty StateDir keeps the ephemeral path for callers without a state dir. This is the foundation for fingerprint-based RP pubkey caching over signalling (NET-1407): a stable local key lets remote peers keep their cached copy valid across our restart.
This commit is contained in:
@@ -551,7 +551,7 @@ func (e *Engine) Start(netbirdConfig *mgmProto.NetbirdConfig, mgmtURL *url.URL)
|
||||
} else {
|
||||
log.Infof("running rosenpass in strict mode")
|
||||
}
|
||||
e.rpManager, err = rosenpass.NewManager(e.config.PreSharedKey, e.config.WgIfaceName, publicKey)
|
||||
e.rpManager, err = rosenpass.NewManager(e.config.PreSharedKey, e.config.WgIfaceName, publicKey, e.config.StateDir)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create rosenpass manager: %w", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user