mirror of
https://github.com/jmcorgan/fips.git
synced 2026-10-05 11:08:25 +00:00
Document that disabling rekey is unsupported and removed in v2
The configuration reference and the mesh-layer design presented node.rekey.enabled: false as an ordinary setting. It is a less-tested path the project does not support, and the option goes away in v2. The flag's behaviour is unchanged.
This commit is contained in:
@@ -374,8 +374,9 @@ A rekey is initiated when either threshold is reached on the link's current
|
|||||||
session: `node.rekey.after_secs` (default 120) elapsed since the link came
|
session: `node.rekey.after_secs` (default 120) elapsed since the link came
|
||||||
up or last rekeyed, or `node.rekey.after_messages` (default 65536) frames
|
up or last rekeyed, or `node.rekey.after_messages` (default 65536) frames
|
||||||
sent. Either side can be the initiator independently. Rekey is on by
|
sent. Either side can be the initiator independently. Rekey is on by
|
||||||
default and can be disabled via `node.rekey.enabled: false` (the
|
default. `node.rekey.enabled: false` stops this node initiating rekey, but
|
||||||
configuration tree is documented in
|
that configuration is unsupported: it is a less-tested path, and the option
|
||||||
|
is removed in v2 (the configuration tree is documented in
|
||||||
[../reference/configuration.md](../reference/configuration.md)).
|
[../reference/configuration.md](../reference/configuration.md)).
|
||||||
|
|
||||||
### Mechanism
|
### Mechanism
|
||||||
|
|||||||
@@ -378,7 +378,7 @@ cutover.
|
|||||||
|
|
||||||
| Parameter | Type | Default | Description |
|
| Parameter | Type | Default | Description |
|
||||||
|-----------|------|---------|-------------|
|
|-----------|------|---------|-------------|
|
||||||
| `node.rekey.enabled` | bool | `true` | Initiate periodic Noise rekey on links and sessions. A peer-driven session rekey is still answered when this is off, so session keys can still rotate |
|
| `node.rekey.enabled` | bool | `true` | Initiate periodic Noise rekey on links and sessions. A peer-driven session rekey is still answered when this is off, so session keys can still rotate. Disabling rekey is unsupported: it runs the node on a less-tested path, and the option is removed in v2. |
|
||||||
| `node.rekey.after_secs` | u64 | `120` | Initiate rekey after this many seconds on a session |
|
| `node.rekey.after_secs` | u64 | `120` | Initiate rekey after this many seconds on a session |
|
||||||
| `node.rekey.after_messages` | u64 | `65536` | Initiate rekey after this many messages sent on a session |
|
| `node.rekey.after_messages` | u64 | `65536` | Initiate rekey after this many messages sent on a session |
|
||||||
|
|
||||||
@@ -1167,6 +1167,7 @@ node:
|
|||||||
loss_threshold: 0.05 # MMP loss rate threshold for CE marking (5%)
|
loss_threshold: 0.05 # MMP loss rate threshold for CE marking (5%)
|
||||||
etx_threshold: 3.0 # MMP ETX threshold for CE marking
|
etx_threshold: 3.0 # MMP ETX threshold for CE marking
|
||||||
rekey:
|
rekey:
|
||||||
|
# enabled: false is unsupported, less tested, and removed in v2
|
||||||
enabled: true # periodic Noise rekey for forward secrecy
|
enabled: true # periodic Noise rekey for forward secrecy
|
||||||
after_secs: 120 # rekey interval (seconds)
|
after_secs: 120 # rekey interval (seconds)
|
||||||
after_messages: 65536 # rekey after N messages sent
|
after_messages: 65536 # rekey after N messages sent
|
||||||
|
|||||||
Reference in New Issue
Block a user