Skip to content

Add DerivedKeystore for fleet-wide cookie sealing - #576

Closed
sofiascalzo wants to merge 1 commit into
facebook:mainfrom
sofiascalzo:export-D114721800
Closed

Add DerivedKeystore for fleet-wide cookie sealing#576
sofiascalzo wants to merge 1 commit into
facebook:mainfrom
sofiascalzo:export-D114721800

Conversation

@sofiascalzo

Copy link
Copy Markdown

Summary:
Fleet-wide NTS cookie keystore: a pure HKDF key-derivation primitive plus the
DerivedKeystore that uses it, so NTS-KE and NTP can seal and open cookies on
different hosts from one shared master, with no shared live state and no
hot-path RPC.

  • deriveCookieKey(master, id) = HKDF-SHA256(master, salt=BE32(id),
    info="fbnts-cookie-seal-v1") -> a masterKeyLen (64-octet) key for the
    AES-SIV-CMAC-512 master AEAD. Pure: no clock, state, or I/O.
  • DerivedKeystore implements the Keystore interface: SealCookie derives a key
    from the master (fixed cookieKeyID) and reuses the existing AES-SIV envelope;
    OpenCookie re-derives from the cookie's Key ID and opens it. No mutex, since
    the master is immutable and derivation is pure. Time-based rotation/windowing
    is deferred to a later change.

Reviewed By: leoleovich

Differential Revision: D114721800

Summary:
Fleet-wide NTS cookie keystore: a pure HKDF key-derivation primitive plus the
DerivedKeystore that uses it, so NTS-KE and NTP can seal and open cookies on
different hosts from one shared master, with no shared live state and no
hot-path RPC.

- deriveCookieKey(master, id) = HKDF-SHA256(master, salt=BE32(id),
  info="fbnts-cookie-seal-v1") -> a masterKeyLen (64-octet) key for the
  AES-SIV-CMAC-512 master AEAD. Pure: no clock, state, or I/O.
- DerivedKeystore implements the Keystore interface: SealCookie derives a key
  from the master (fixed cookieKeyID) and reuses the existing AES-SIV envelope;
  OpenCookie re-derives from the cookie's Key ID and opens it. No mutex, since
  the master is immutable and derivation is pure. Time-based rotation/windowing
  is deferred to a later change.

Reviewed By: leoleovich

Differential Revision: D114721800
@meta-cla meta-cla Bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Aug 5, 2026
@meta-codesync

meta-codesync Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

@sofiascalzo has exported this pull request. If you are a Meta employee, you can view the originating Diff in D114721800.

@meta-codesync

meta-codesync Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

This pull request has been merged in a9bbda8.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. Merged meta-exported

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant