Two nodes with same key?

Graham Cobb g+tinc at cobb.uk.net
Mon May 11 19:43:22 CEST 2015


I am wondering if tinc breaks if two hosts have the same key?  I am
guessing it probably does!

I have a hub-and-spoke arrangement, with VPN clients who all know the
DNS name and the public key for the hub.  I need to transition the hub
to another server, with another IP address.  I will, after testing,
transition the DNS name to point to the new server.

It would be convenient if I didn't have to update all the clients with a
new key for the new server.  And certainly not all at the same time.

So, it would be useful if I could install the same key on both the old
and the new server while I test and transition to the new server.  And
if I then switch the name over, the clients would not need to have any
modifications at all.

But during the testing and transition period, I want to keep the VPN
connected, so I had planned to connect the old hub and the new hub.  But
this would mean two nodes with the same key (and the same name, but I
assume tinc host names are only meaningful locally) on the network
(connected directly to each other).  This would last until testing of
the new hub is complete, the DNS name is switched to the new hub and the
old hub is shut down.

If this won't work, I can either break connectivity until I can switch
the DNS names, or I run something like rinetd on the old hub to forward
tinc traffic to the new hub.

Graham


More information about the tinc mailing list