github netbirdio/netbird v0.81.0-canary.pr-7890.1

pre-release4 hours ago

Changelog

  • 88d8baa Time the lost-collection wait from the oldest collection still running
  • 2f66426 Merge branch 'certificate-posture-client' into rm_certs_posture_chk
  • ab75020 Fix the pending checks comments
  • 6f0dcfe Accept only whole-second challenge windows of at least 30 seconds
  • a990266 Start the certificate challenge refresher only once the account manager is built
  • e02c382 Keep an account tracked for certificate challenges when it is tracked again during its refresh
  • d9f1a94 Let a lost proof collection go after ten deadlines, sharing the slots across engine restarts
  • 23a7809 Merge certificate-posture-client into rm_certs_posture_chk
  • 3d629c5 Close a PKCS#11 module that loads but cannot be used
  • f603251 Share the proof collection single-flight across engine restarts
  • d70249a Report no lost certificate when the engine stops during a proof collection
  • 4ad5c16 Keep the newest posture checks pending whatever made their meta sync fail
  • 0dab171 [management] Keep the certificate challenge comments to what the history does not say
  • f1ed3a7 [management] Send challenge refreshes down the path the rest of management uses
  • 7cc95f6 [management] Bound one account's challenge refresh so it cannot starve the rest
  • 3269d81 [management] Let the challenge refresh loop stop with the manager that owns it
  • 3d9def7 [management] Register for renewal on pushed updates, not only on connect
  • c62cda3 [management] Register an account for renewal where its nonce is issued
  • a0fa325 [management] Derive certificate challenge nonces from the stored encryption key
  • 4e42ccb [management] Renew challenges only for the peers that answer one
  • 689ab05 [management] Pin the property that makes per-peer nonce state unnecessary
  • c2d2f76 [management] Make the certificate challenge window one knob to turn
  • f490f09 [management] Renew certificate challenge nonces on quiet accounts
  • eaf6bec Drop the certificate store directory from certproof.Config, which only NB_CERT_STORE_DIR sets
  • 4b31962 Name the post-install permission helper in snake case and shorten the sysconfig certificate block
  • db24bd3 Keep free functions out of the method lists of PKCS11Store, URI and Challenger
  • fb56c2d Hold off the keychain helper only after a completed or timed-out run, independent of CA order
  • c2fe712 Clear the lint findings in certificate posture
  • b2a99b6 Ask a macOS user's keychain again only after an hour when it proved nothing
  • 3b67491 Let the certificate proof helper read the PKCS#11 token from the environment on Linux
  • c50545c Search only the System keychain in the macOS daemon and only the login keychain in the user helper
  • f311fd5 Restrict the service environment file to root on every package install
  • ffbd896 Give the full import command for a keychain key netbird may not use, and correct the package doc
  • 63642bb Keep the file check results of the latest-started system info refresh
  • 2017987 Name NB_CERT_PKCS11_URI in the PIN-without-token error
  • 260c149 Move the certificate posture README into the package doc and the docs site
  • c1520fe Install the RPM sysconfig file readable by root only and show the certificate posture variables
  • a45cbec Read the certificate store directory and PKCS#11 URI from the daemon environment, not the profile config
  • ea63acb Collect certificate proofs on the posture watcher instead of under the sync lock
  • 9c4da8d Hold off system info gathering only while a timed-out one is still running
  • c5f2f6a End sudo option parsing before the macOS certificate helper binary
  • d85f2e5 Kill the whole macOS certificate helper process group when it times out
  • 441cf94 Explain a macOS keychain key whose access list does not allow netbird
  • 60776de Send recollected certificate proofs to management only when the proven chains changed
  • 5764ddd Log what a successful certificate proof helper wrote to stderr
  • 8b38697 Guard the applied posture checks across goroutines and keep refreshing proofs while a pending update times out
  • 4da7a2e Start no system info gathering while a timed-out one is still running
  • bff0ea0 Retry posture checks whose meta sync timed out instead of dropping them
  • 0cdcc9d Merge commit '09b19595f' into certificate-posture-client
  • 09b1959 Add the certificate fields to the network map golden data
  • a66b3e0 Merge main through poc/certificate-posture
  • ea5cf82 Merge main into poc/certificate-posture
  • c39047e Refuse a TPM PSS signature request for the maximum salt length
  • eb5a98c [management] add tenant delete endpoint to openapi (#8054)
  • 2b52936 [client] Skip late session warnings on desktop and schedule them in the app on Android (#7548)
  • 5c3cca2 Test that the PKCS#11 URI stays out of the debug bundle and run the wrong-PIN test only on a disposable token
  • 597f198 Document the PIN sources on CertPKCS11URI and keep the README PIN example off the command line
  • 6d9b8e6 Use no user certificate store when the active profile's owner cannot be read
  • 4209a78 Use no Windows user store when a domainless owner matches accounts of several domains
  • 5682247 Collect certificate proofs again when the meta sync carrying them failed
  • f175e40 [client] stop offering to every peer when the relay transport drops (#7092)
  • 0e46d95 Share a PKCS#11 login between sessions and send each PIN at most once at a time
  • 44312b4 Check the store directory before listing it, refuse group-writable files, and reject a URI with two PIN sources
  • dc3101a Count the certificates field in the peer meta store test
  • 53108c7 Accept the TSS2 emptyAuth boolean OpenSSL writes and persistent parents on 32-bit builds
  • ad03081 [management] Refresh only affected peers on IPv6 settings changes (#8051)
  • bc44cdc [client] Fix browser login popup show from go (#7408)
  • 26fe2c5 [client] Clear the lint findings only the macOS and Windows runners see
  • cc12110 [client] Drop go.step.sm/crypto and the repo-wide upgrades it imposed
  • 8d9e125 [client] Read TSS2 key files on go-tpm, checked against the library it replaces
  • 6b3cfba [client] Resolve the Android network route peer by HA unique ID instead of scanning the full status (#7705)
  • 1c7d87d [client,android] Generate debug bundle to file (#7528)
  • 13ce674 Keep the certificate stores and TPM library out of the WebAssembly build
  • 19c54b8 [management] Refresh only affected peers on DNS zone and record changes (#8050)
  • 0cd27ca [management] Improve Base62 encoding/decoding performance and robustness (#3391)
  • 8f138c0 Match the Windows profile owner by name instead of resolving it through the domain controller
  • 86c5ca0 Use platform absolute module paths in tests and add a real owner session test for Windows
  • 6262325 Explain a Windows certificate whose key only a legacy CryptoAPI provider holds
  • a12f19c Trust certificate and key files only when no other user can write or redirect them
  • 7b8fa29 [self-hosted] Replace "which" dependency by "command" from configure.sh script (#8007)
  • 0892712 Refuse PKCS#11 URIs that this client cannot honour instead of widening the match
  • 249793d Document where an inline PKCS#11 PIN is stored and how it is protected
  • 88b26bb [infrastructure] Create the preflight artifacts directory before submitting (#7947)
  • 3c4358d [management] Require a private proxy cluster for cluster and direct upstream targets (#7984)
  • e89acf5 [client] Take the caller's context and the lock when collecting proofs
  • 58142f3 [client] Let a wedged proof collection go, instead of disabling proofs for good
  • 73655fb [client] Clear the lint findings only the macOS and Windows runners see
  • 278f2f3 [management] Derive certificate challenge nonces from the stored encryption key
  • 8d22607 [client] Drop go.step.sm/crypto and the repo-wide upgrades it imposed
  • a7f183c [client] Read TSS2 key files on go-tpm, checked against the library it replaces
  • dc4d0e0 [management] Renew challenges only for the peers that answer one
  • dee68fa [management] Pin the property that makes per-peer nonce state unnecessary
  • 0e38fcf [management] Make the certificate challenge window one knob to turn
  • 7ad4a0d [management] Renew certificate challenge nonces on quiet accounts
  • 3e360eb [client] Drop the unreachable helper timeout from certificate proof collection
  • ec48a92 [client] Cover the cert proof helper path the deadline actually cuts short
  • 8224e0f [client] Bound the wait on a certificate proof helper that outlives its launcher
  • 9f8ddc7 [client] Discover interfaces lazily in stdnet instead of at construction (#7346)
  • 1b89880 [misc] Move the FreeBSD port test to release 15.1 (#7999)
  • e2678d4 [management] expose peer MAC addresses and make peers searchable by MAC (#6553)
  • 0712a5a [management,proxy] Rename the OIDC session code query parameter (#7981)
  • 0ed3eb6 Test the PKCS#11 build against SoftHSM in CI and warn once where the build has no driver
  • 07cf082 Collect certificate proofs again when the owner's session changes and report lost proofs
  • a91fe94 Read user certificates only from the session of the active profile's owner
  • e0b6a38 Require a token label whenever a PKCS#11 PIN is set
  • f400f4b [proxy] Optionally refuse private addresses on direct-upstream dials (#7913)
  • 5ceca6e [client] Report both peers' state when the connect test times out (#7944)
  • 3906295 [client] Add Homebrew cask e2e test (#7618)
  • 6425b04 [client] Only treat LocalSystem as a privileged identity by SID on Windows (#7889)
  • 3cfff34 Find a chain to each challenge's CAs through every intermediate the store holds
  • 21be442 Keep the macOS keychain code out of iOS and the PKCS#11 driver out of Android
  • 06bc8bf Never pass NULL to CFRelease and skip unreadable keychain identities
  • b364af9 Bound PKCS#11 driver sizes, pin template values, and log out only a login the session owns
  • 59aeeb1 Skip certificate files whose key belongs to another certificate
  • 5af909b Sign only nonces and peer keys of the size management issues
  • 0129b90 Log certificate posture details at debug level
  • a230d39 Stop retrying a PKCS#11 PIN the token rejected
  • 83e7bf8 Bound certificate proof collection so a stuck token or keychain cannot hold the sync loop
  • ab2f897 Read the PKCS#11 token PIN from NB_TPM_PIN instead of the profile config
  • 0641f0d Isolate the cert proof helper from the service environment and cap its output
  • 82e5428 [management] Let usage_viewer read Agent Network access logs (#7750)
  • fd1a020 [management] Clean up after account deletion (#7812)
  • 6c453a0 [client] Add debug cpu start and stop commands (#7749)
  • 0dc729c [client] Cache the box shared key per remote peer in the Signal client (#7807)
  • e72be66 [client] Keep the advertised ICE session ID when following a remote restart (#7814)
  • 39de33c [management] handle db conn close on errpr (#7740)
  • 96bfcc3 [client] Classify Windows local accounts by NetBIOS name (#7628)
  • 8ab34fc [proxy] Apply the upstream HTTP version before cloning transports (#7806)
  • 8edc120 [client] Replace the eBPF WireGuard proxy with loopback endpoint addressing (#7316)
  • 574c299 add unsupported flag for mobile devices
  • 30dd076 [management,proxy] Use single-use codes for OIDC session handoff (#7635)
  • 7ff709f [client] Keep the delete-profile dialog open until the delete finishes (#7752)
  • 10a04fc [management] Add a disabled state to the managed Agent Network proxy API (#7744)
  • 93cb226 [management] fix login filter (#7739)
  • 082aca1 [management] Refactor PKCE verifier store into a reusable single-use store (#7634)
  • a2919e2 [management, proxy] Enforce strict base64url decoding for JWT validation (#7554)
  • e830903 [management] Add a revocation guard hook to the proxy token API (#7732)
  • 782c943 [management] extract shared db conn + data repository (#7649)
  • 002755c [infrastructure] Fix flow auth secret for external Relay migrations (#7731)
  • 164d92e [client] Stop dumping the whole device to clear one peer endpoint (#7632)
  • 7fbde60 split cert and key location and allow key lookup on tpm
  • d04aef6 add tpm pin to netbird config
  • d3c5b67 Merge branch 'main' into poc/certificate-posture
  • af7b475 go mod tidy
  • a2e66a7 Merge branch 'main' into poc/certificate-posture
  • 47318da update goreleaser
  • 92d76ac split goreleaser to support pkcs11 and exclude on docker
  • 25078c4 Merge branch 'main' into poc/certificate-posture
  • 24f5f2a start TPM support
  • d89e9c8 Merge remote-tracking branch 'origin/main' into poc/certificate-posture
  • e0ede59 read the signed-in user's certificate store on Windows
  • 422912e read the console user's keychain through a user session helper
  • 068f218 add keychain and cert store support
  • 6c910ed Merge branch 'main' into poc/certificate-posture
  • aea3f4f log signal address
  • 8c5cf86 Merge remote-tracking branch 'origin/main' into poc/certificate-posture
  • 84d83fa implement certificate posture check

Don't miss a new netbird release

NewReleases is sending notifications on new releases.