Files
Johnathan Corgan b0c36a9d7d Warn on Windows about fips.yaml and fips.key in \etc\fips
The config search still probes the drive-relative \etc\fips\fips.yaml on
Windows, where any local user can create files, and merges it under the
real config. A node upgraded from a hand-made service that ran from
\etc\fips now reads only C:\ProgramData\fips and silently comes up with a
new identity.

Log a warning when a config was loaded from \etc\fips, saying the search
stops looking there in v0.6.0; it is logged before identity resolution,
so a start that fails on a key the file supplied still names the file.
After resolution, warn when fips.yaml or fips.key is there but this run
did not use it, counting a key generated this run as in use. Paths are
compared the way Windows does, with either separator, any case and any
drive prefix, so an explicit C:\etc\fips\fips.yaml given with -c or
FIPS_CONFIG is recognised. The decision is a pure function tested on
every platform; the key is only checked for presence, never read.
2026-10-01 14:20:06 +00:00
..