From 0277a72b79e6cd0aa2768c2752c314ec201d8977 Mon Sep 17 00:00:00 2001 From: Johnathan Corgan Date: Wed, 30 Sep 2026 13:46:23 +0000 Subject: [PATCH] Document that disabling rekey is unsupported and removed in v2 The configuration reference and the mesh-layer design presented node.rekey.enabled: false as an ordinary setting. It is a less-tested path the project does not support, and the option goes away in v2. The flag's behaviour is unchanged. --- docs/design/fips-mesh-layer.md | 5 +++-- docs/reference/configuration.md | 3 ++- 2 files changed, 5 insertions(+), 3 deletions(-) diff --git a/docs/design/fips-mesh-layer.md b/docs/design/fips-mesh-layer.md index b437fa22..eb7d5b0d 100644 --- a/docs/design/fips-mesh-layer.md +++ b/docs/design/fips-mesh-layer.md @@ -374,8 +374,9 @@ A rekey is initiated when either threshold is reached on the link's current session: `node.rekey.after_secs` (default 120) elapsed since the link came up or last rekeyed, or `node.rekey.after_messages` (default 65536) frames sent. Either side can be the initiator independently. Rekey is on by -default and can be disabled via `node.rekey.enabled: false` (the -configuration tree is documented in +default. `node.rekey.enabled: false` stops this node initiating rekey, but +that configuration is unsupported: it is a less-tested path, and the option +is removed in v2 (the configuration tree is documented in [../reference/configuration.md](../reference/configuration.md)). ### Mechanism diff --git a/docs/reference/configuration.md b/docs/reference/configuration.md index 9da7f87e..05006695 100644 --- a/docs/reference/configuration.md +++ b/docs/reference/configuration.md @@ -378,7 +378,7 @@ cutover. | Parameter | Type | Default | Description | |-----------|------|---------|-------------| -| `node.rekey.enabled` | bool | `true` | Initiate periodic Noise rekey on links and sessions. A peer-driven session rekey is still answered when this is off, so session keys can still rotate | +| `node.rekey.enabled` | bool | `true` | Initiate periodic Noise rekey on links and sessions. A peer-driven session rekey is still answered when this is off, so session keys can still rotate. Disabling rekey is unsupported: it runs the node on a less-tested path, and the option is removed in v2. | | `node.rekey.after_secs` | u64 | `120` | Initiate rekey after this many seconds on a session | | `node.rekey.after_messages` | u64 | `65536` | Initiate rekey after this many messages sent on a session | @@ -1167,6 +1167,7 @@ node: loss_threshold: 0.05 # MMP loss rate threshold for CE marking (5%) etx_threshold: 3.0 # MMP ETX threshold for CE marking rekey: + # enabled: false is unsupported, less tested, and removed in v2 enabled: true # periodic Noise rekey for forward secrecy after_secs: 120 # rekey interval (seconds) after_messages: 65536 # rekey after N messages sent