feat: replace connection keys with short seed-derived rtun3 keys
CI / cargo fmt (push) Canceled after 0s
CI / cargo clippy (macos-latest) (push) Canceled after 0s
CI / cargo clippy (ubuntu-latest) (push) Canceled after 0s
CI / cargo clippy (windows-latest) (push) Canceled after 0s
CI / cargo test (macos-latest) (push) Canceled after 0s
CI / cargo test (ubuntu-latest) (push) Canceled after 0s
CI / cargo test (windows-latest) (push) Canceled after 0s
CI / cargo build (macos-latest) (push) Canceled after 0s
CI / cargo build (ubuntu-latest) (push) Canceled after 0s
CI / cargo build (windows-latest) (push) Canceled after 0s
CI / cargo build --release (macos-latest) (push) Canceled after 0s
CI / cargo build --release (ubuntu-latest) (push) Canceled after 0s
CI / cargo build --release (windows-latest) (push) Canceled after 0s
CI / CLI smoke (macos-latest) (push) Canceled after 0s
CI / CLI smoke (ubuntu-latest) (push) Canceled after 0s
CI / CLI smoke (windows-latest) (push) Canceled after 0s
CI / Minimal E2E (macos-latest) (push) Canceled after 0s
CI / Minimal E2E (ubuntu-latest) (push) Canceled after 0s
CI / Minimal E2E (windows-latest) (push) Canceled after 0s
CI / cargo fmt (push) Canceled after 0s
CI / cargo clippy (macos-latest) (push) Canceled after 0s
CI / cargo clippy (ubuntu-latest) (push) Canceled after 0s
CI / cargo clippy (windows-latest) (push) Canceled after 0s
CI / cargo test (macos-latest) (push) Canceled after 0s
CI / cargo test (ubuntu-latest) (push) Canceled after 0s
CI / cargo test (windows-latest) (push) Canceled after 0s
CI / cargo build (macos-latest) (push) Canceled after 0s
CI / cargo build (ubuntu-latest) (push) Canceled after 0s
CI / cargo build (windows-latest) (push) Canceled after 0s
CI / cargo build --release (macos-latest) (push) Canceled after 0s
CI / cargo build --release (ubuntu-latest) (push) Canceled after 0s
CI / cargo build --release (windows-latest) (push) Canceled after 0s
CI / CLI smoke (macos-latest) (push) Canceled after 0s
CI / CLI smoke (ubuntu-latest) (push) Canceled after 0s
CI / CLI smoke (windows-latest) (push) Canceled after 0s
CI / Minimal E2E (macos-latest) (push) Canceled after 0s
CI / Minimal E2E (ubuntu-latest) (push) Canceled after 0s
CI / Minimal E2E (windows-latest) (push) Canceled after 0s
Connection keys are now a ~49-char seed (rtun3.) instead of a bundled ~1740-char certificate blob. Both endpoints deterministically derive an identical Ed25519 CA from the seed and mint ephemeral server/client leaves at startup (keyderive.rs); the app-layer auth token is derived from the seed. Target is passed separately on connect (resocks-style). - connkey.rs: rtun3 seed parse/format - keyderive.rs: CA/server/client/token derivation - keygen takes no args; connect requires --target - remove miniz_oxide; TLS layer unchanged - add determinism + key-based e2e + wrong-seed-rejected tests - update wiki, README, design spec, CI smoke
This commit is contained in:
@@ -10,7 +10,7 @@ Start the HTTPS tunnel listener. Binds an HTTPS server that accepts mTLS connect
|
||||
|
||||
Key arguments:
|
||||
- `--listen` — bind address (default `0.0.0.0:4180`)
|
||||
- `--advertise` — public address embedded in auto-generated connection keys
|
||||
- `--advertise` — public host added to the derived server cert and used in the printed connect hint
|
||||
- `--connection-key` — reusable key generated by `keygen` or a previous `listen` run
|
||||
- `--socks` — optional server-side SOCKS5 proxy address for connector-side network access
|
||||
- `--cert`, `--key`, `--ca-cert` — TLS material paths (required unless using a connection key)
|
||||
@@ -25,7 +25,7 @@ Connect to the listener and expose a local SOCKS5 proxy.
|
||||
|
||||
Key arguments:
|
||||
- `CONNECTION_KEY` — positional connection key (optional)
|
||||
- `--target` — listener address (default from connection key)
|
||||
- `--target` — listener address (required; not stored in the key)
|
||||
- `--connection-key` — connection key via flag or env `RUSTUNNEL_KEY`
|
||||
- `--socks` — local SOCKS5 proxy address (default `127.0.0.1:1180`)
|
||||
- `--cert`, `--key`, `--ca-cert` — TLS material paths (required unless using a connection key)
|
||||
@@ -39,7 +39,9 @@ Creates: `ca.pem`, `ca.key`, `server.crt`, `server.key`, `client.crt`, `client.k
|
||||
|
||||
### `keygen`
|
||||
|
||||
Generate a single reusable connection key string. This bundles all certificate material, the auth token, and the target address into a base64url-encoded, DEFLATE-compressed JSON blob prefixed with `rtun2.`.
|
||||
Print a fresh ~49-char connection key (prefix `rtun3.`). The key is a random 32-byte
|
||||
seed from which both endpoints derive identical TLS material; no certificates are
|
||||
shipped. Pass the target address separately on `connect`.
|
||||
|
||||
### `version`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user