Files
fips/packaging/windows
Johnathan Corgan ee453c56ea Stop the Windows installer when \etc\fips holds the only identity key
A service that earlier releases ran from \etc\fips reads only
C:\ProgramData\fips once the installer sets FIPS_CONFIG, so it came up
with a new npub and address with nothing said. The installer now stops,
before it creates any file or copies the binaries, when
\etc\fips\fips.key exists and C:\ProgramData\fips\fips.key does not, and
says to move the key and its settings and delete the old fips.yaml. It
does not move the key itself, since any local user can write to
\etc\fips. A packaging test pins the condition, the Write-Error and
exit, and the refusal's place ahead of file creation, the binary copy and
service registration.

The ZIP README gave the foreground config search as starting at
C:\ProgramData\fips, but \etc\fips\fips.yaml on the current drive is
probed first and any local user can create it. List it, with the
daemon's warning and the search no longer looking there in v0.6.0.
Describe the installer's stop, and give the upgrade steps: rerunning the
installer while the service runs fails copying fips.exe.
2026-10-01 14:20:06 +00:00
..