Documentation ¶
Overview ¶
Program tl-longchain prints commands to re-sign Tailscale nodes that have long rotation signature chains.
There is an implicit limit on the number of rotation signatures that can be chained before the signature becomes too long. This program helps tailnet admins to identify nodes that have signatures with long chains and prints commands to re-sign those node keys with a fresh direct signature. Commands are printed to stdout, while log messages are printed to stderr.
Note that the Tailscale client this command is executed on must have ACL visibility to all other nodes to be able to see their signatures. https://tailscale.com/kb/1087/device-visibility
Click to show internal directories.
Click to hide internal directories.