You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
An attempt to #7971 (ledger signing part), with already quite a few changes (the more effort I put in, the more I lean towards simplifying things).
This's an ☔ for subtasks/PRs, to keep track of PQ signing completion in general.
Why?
As we want PQ update to be a live code update, and as we want identities rotation flexibility, there's a separate ticket to solve that: Flexible service identity rotation #8264.
This ticket focuses on supporting multiple signing identities for new or DR-ed services.
Big change to endorsement chain handling, same KV change as for signatures
Separately, when recovering from a snapshot, a different endorsement handling mechanism is in use, needs handling different endorsement types
Endpoints/interfaces to serve signing keys for external/internal use cases, currently TBD
Config-enabled PQ on service-recover/create (with e2e coverage on AL4)
Workflow change
On fresh network start or recovery, the identity choice is determined by the config
Signing identities are distributed alongside the existing service TLS identity on Join request, always in sync (until rotation is solved)
Removing identity type is currently prohibited, as in CLASSICAL+PQ to a single is disallowed
allows to have a realistic scope of changes, and keep endorsement chain contract
later on, we can come up with identity termination, but there's no plan for such a need rn, as HYBRID signing is what we're aiming for the foreseeable future
An attempt to #7971 (ledger signing part), with already quite a few changes (the more effort I put in, the more I lean towards simplifying things).
This's an ☔ for subtasks/PRs, to keep track of PQ signing completion in general.
Why?
Structural changes planned in this one
previous_service_identityand replace withprevious_signing_keyswhich will hold multiple {KeyType->Key} ("Previous service signing keys" replace cert #8477)previous_signing_keysand markprevious_service_identityas deprecated, that table will be gone in 8.xWorkflow change