Changelog
- 88d8baa Time the lost-collection wait from the oldest collection still running
- 2f66426 Merge branch 'certificate-posture-client' into rm_certs_posture_chk
- ab75020 Fix the pending checks comments
- 6f0dcfe Accept only whole-second challenge windows of at least 30 seconds
- a990266 Start the certificate challenge refresher only once the account manager is built
- e02c382 Keep an account tracked for certificate challenges when it is tracked again during its refresh
- d9f1a94 Let a lost proof collection go after ten deadlines, sharing the slots across engine restarts
- 23a7809 Merge certificate-posture-client into rm_certs_posture_chk
- 3d629c5 Close a PKCS#11 module that loads but cannot be used
- f603251 Share the proof collection single-flight across engine restarts
- d70249a Report no lost certificate when the engine stops during a proof collection
- 4ad5c16 Keep the newest posture checks pending whatever made their meta sync fail
- 0dab171 [management] Keep the certificate challenge comments to what the history does not say
- f1ed3a7 [management] Send challenge refreshes down the path the rest of management uses
- 7cc95f6 [management] Bound one account's challenge refresh so it cannot starve the rest
- 3269d81 [management] Let the challenge refresh loop stop with the manager that owns it
- 3d9def7 [management] Register for renewal on pushed updates, not only on connect
- c62cda3 [management] Register an account for renewal where its nonce is issued
- a0fa325 [management] Derive certificate challenge nonces from the stored encryption key
- 4e42ccb [management] Renew challenges only for the peers that answer one
- 689ab05 [management] Pin the property that makes per-peer nonce state unnecessary
- c2d2f76 [management] Make the certificate challenge window one knob to turn
- f490f09 [management] Renew certificate challenge nonces on quiet accounts
- eaf6bec Drop the certificate store directory from certproof.Config, which only NB_CERT_STORE_DIR sets
- 4b31962 Name the post-install permission helper in snake case and shorten the sysconfig certificate block
- db24bd3 Keep free functions out of the method lists of PKCS11Store, URI and Challenger
- fb56c2d Hold off the keychain helper only after a completed or timed-out run, independent of CA order
- c2fe712 Clear the lint findings in certificate posture
- b2a99b6 Ask a macOS user's keychain again only after an hour when it proved nothing
- 3b67491 Let the certificate proof helper read the PKCS#11 token from the environment on Linux
- c50545c Search only the System keychain in the macOS daemon and only the login keychain in the user helper
- f311fd5 Restrict the service environment file to root on every package install
- ffbd896 Give the full import command for a keychain key netbird may not use, and correct the package doc
- 63642bb Keep the file check results of the latest-started system info refresh
- 2017987 Name NB_CERT_PKCS11_URI in the PIN-without-token error
- 260c149 Move the certificate posture README into the package doc and the docs site
- c1520fe Install the RPM sysconfig file readable by root only and show the certificate posture variables
- a45cbec Read the certificate store directory and PKCS#11 URI from the daemon environment, not the profile config
- ea63acb Collect certificate proofs on the posture watcher instead of under the sync lock
- 9c4da8d Hold off system info gathering only while a timed-out one is still running
- c5f2f6a End sudo option parsing before the macOS certificate helper binary
- d85f2e5 Kill the whole macOS certificate helper process group when it times out
- 441cf94 Explain a macOS keychain key whose access list does not allow netbird
- 60776de Send recollected certificate proofs to management only when the proven chains changed
- 5764ddd Log what a successful certificate proof helper wrote to stderr
- 8b38697 Guard the applied posture checks across goroutines and keep refreshing proofs while a pending update times out
- 4da7a2e Start no system info gathering while a timed-out one is still running
- bff0ea0 Retry posture checks whose meta sync timed out instead of dropping them
- 0cdcc9d Merge commit '09b19595f' into certificate-posture-client
- 09b1959 Add the certificate fields to the network map golden data
- a66b3e0 Merge main through poc/certificate-posture
- ea5cf82 Merge main into poc/certificate-posture
- c39047e Refuse a TPM PSS signature request for the maximum salt length
- eb5a98c [management] add tenant delete endpoint to openapi (#8054)
- 2b52936 [client] Skip late session warnings on desktop and schedule them in the app on Android (#7548)
- 5c3cca2 Test that the PKCS#11 URI stays out of the debug bundle and run the wrong-PIN test only on a disposable token
- 597f198 Document the PIN sources on CertPKCS11URI and keep the README PIN example off the command line
- 6d9b8e6 Use no user certificate store when the active profile's owner cannot be read
- 4209a78 Use no Windows user store when a domainless owner matches accounts of several domains
- 5682247 Collect certificate proofs again when the meta sync carrying them failed
- f175e40 [client] stop offering to every peer when the relay transport drops (#7092)
- 0e46d95 Share a PKCS#11 login between sessions and send each PIN at most once at a time
- 44312b4 Check the store directory before listing it, refuse group-writable files, and reject a URI with two PIN sources
- dc3101a Count the certificates field in the peer meta store test
- 53108c7 Accept the TSS2 emptyAuth boolean OpenSSL writes and persistent parents on 32-bit builds
- ad03081 [management] Refresh only affected peers on IPv6 settings changes (#8051)
- bc44cdc [client] Fix browser login popup show from go (#7408)
- 26fe2c5 [client] Clear the lint findings only the macOS and Windows runners see
- cc12110 [client] Drop go.step.sm/crypto and the repo-wide upgrades it imposed
- 8d9e125 [client] Read TSS2 key files on go-tpm, checked against the library it replaces
- 6b3cfba [client] Resolve the Android network route peer by HA unique ID instead of scanning the full status (#7705)
- 1c7d87d [client,android] Generate debug bundle to file (#7528)
- 13ce674 Keep the certificate stores and TPM library out of the WebAssembly build
- 19c54b8 [management] Refresh only affected peers on DNS zone and record changes (#8050)
- 0cd27ca [management] Improve Base62 encoding/decoding performance and robustness (#3391)
- 8f138c0 Match the Windows profile owner by name instead of resolving it through the domain controller
- 86c5ca0 Use platform absolute module paths in tests and add a real owner session test for Windows
- 6262325 Explain a Windows certificate whose key only a legacy CryptoAPI provider holds
- a12f19c Trust certificate and key files only when no other user can write or redirect them
- 7b8fa29 [self-hosted] Replace "which" dependency by "command" from configure.sh script (#8007)
- 0892712 Refuse PKCS#11 URIs that this client cannot honour instead of widening the match
- 249793d Document where an inline PKCS#11 PIN is stored and how it is protected
- 88b26bb [infrastructure] Create the preflight artifacts directory before submitting (#7947)
- 3c4358d [management] Require a private proxy cluster for cluster and direct upstream targets (#7984)
- e89acf5 [client] Take the caller's context and the lock when collecting proofs
- 58142f3 [client] Let a wedged proof collection go, instead of disabling proofs for good
- 73655fb [client] Clear the lint findings only the macOS and Windows runners see
- 278f2f3 [management] Derive certificate challenge nonces from the stored encryption key
- 8d22607 [client] Drop go.step.sm/crypto and the repo-wide upgrades it imposed
- a7f183c [client] Read TSS2 key files on go-tpm, checked against the library it replaces
- dc4d0e0 [management] Renew challenges only for the peers that answer one
- dee68fa [management] Pin the property that makes per-peer nonce state unnecessary
- 0e38fcf [management] Make the certificate challenge window one knob to turn
- 7ad4a0d [management] Renew certificate challenge nonces on quiet accounts
- 3e360eb [client] Drop the unreachable helper timeout from certificate proof collection
- ec48a92 [client] Cover the cert proof helper path the deadline actually cuts short
- 8224e0f [client] Bound the wait on a certificate proof helper that outlives its launcher
- 9f8ddc7 [client] Discover interfaces lazily in stdnet instead of at construction (#7346)
- 1b89880 [misc] Move the FreeBSD port test to release 15.1 (#7999)
- e2678d4 [management] expose peer MAC addresses and make peers searchable by MAC (#6553)
- 0712a5a [management,proxy] Rename the OIDC session code query parameter (#7981)
- 0ed3eb6 Test the PKCS#11 build against SoftHSM in CI and warn once where the build has no driver
- 07cf082 Collect certificate proofs again when the owner's session changes and report lost proofs
- a91fe94 Read user certificates only from the session of the active profile's owner
- e0b6a38 Require a token label whenever a PKCS#11 PIN is set
- f400f4b [proxy] Optionally refuse private addresses on direct-upstream dials (#7913)
- 5ceca6e [client] Report both peers' state when the connect test times out (#7944)
- 3906295 [client] Add Homebrew cask e2e test (#7618)
- 6425b04 [client] Only treat LocalSystem as a privileged identity by SID on Windows (#7889)
- 3cfff34 Find a chain to each challenge's CAs through every intermediate the store holds
- 21be442 Keep the macOS keychain code out of iOS and the PKCS#11 driver out of Android
- 06bc8bf Never pass NULL to CFRelease and skip unreadable keychain identities
- b364af9 Bound PKCS#11 driver sizes, pin template values, and log out only a login the session owns
- 59aeeb1 Skip certificate files whose key belongs to another certificate
- 5af909b Sign only nonces and peer keys of the size management issues
- 0129b90 Log certificate posture details at debug level
- a230d39 Stop retrying a PKCS#11 PIN the token rejected
- 83e7bf8 Bound certificate proof collection so a stuck token or keychain cannot hold the sync loop
- ab2f897 Read the PKCS#11 token PIN from NB_TPM_PIN instead of the profile config
- 0641f0d Isolate the cert proof helper from the service environment and cap its output
- 82e5428 [management] Let usage_viewer read Agent Network access logs (#7750)
- fd1a020 [management] Clean up after account deletion (#7812)
- 6c453a0 [client] Add debug cpu start and stop commands (#7749)
- 0dc729c [client] Cache the box shared key per remote peer in the Signal client (#7807)
- e72be66 [client] Keep the advertised ICE session ID when following a remote restart (#7814)
- 39de33c [management] handle db conn close on errpr (#7740)
- 96bfcc3 [client] Classify Windows local accounts by NetBIOS name (#7628)
- 8ab34fc [proxy] Apply the upstream HTTP version before cloning transports (#7806)
- 8edc120 [client] Replace the eBPF WireGuard proxy with loopback endpoint addressing (#7316)
- 574c299 add unsupported flag for mobile devices
- 30dd076 [management,proxy] Use single-use codes for OIDC session handoff (#7635)
- 7ff709f [client] Keep the delete-profile dialog open until the delete finishes (#7752)
- 10a04fc [management] Add a disabled state to the managed Agent Network proxy API (#7744)
- 93cb226 [management] fix login filter (#7739)
- 082aca1 [management] Refactor PKCE verifier store into a reusable single-use store (#7634)
- a2919e2 [management, proxy] Enforce strict base64url decoding for JWT validation (#7554)
- e830903 [management] Add a revocation guard hook to the proxy token API (#7732)
- 782c943 [management] extract shared db conn + data repository (#7649)
- 002755c [infrastructure] Fix flow auth secret for external Relay migrations (#7731)
- 164d92e [client] Stop dumping the whole device to clear one peer endpoint (#7632)
- 7fbde60 split cert and key location and allow key lookup on tpm
- d04aef6 add tpm pin to netbird config
- d3c5b67 Merge branch 'main' into poc/certificate-posture
- af7b475 go mod tidy
- a2e66a7 Merge branch 'main' into poc/certificate-posture
- 47318da update goreleaser
- 92d76ac split goreleaser to support pkcs11 and exclude on docker
- 25078c4 Merge branch 'main' into poc/certificate-posture
- 24f5f2a start TPM support
- d89e9c8 Merge remote-tracking branch 'origin/main' into poc/certificate-posture
- e0ede59 read the signed-in user's certificate store on Windows
- 422912e read the console user's keychain through a user session helper
- 068f218 add keychain and cert store support
- 6c910ed Merge branch 'main' into poc/certificate-posture
- aea3f4f log signal address
- 8c5cf86 Merge remote-tracking branch 'origin/main' into poc/certificate-posture
- 84d83fa implement certificate posture check