問題文
For request forwarding, the standby nodes need to talk to the active node directly. How is that channel secured, and where do the nodes learn what they need?
選択肢
- The nodes exchange the material over the cluster port at startup using an unauthenticated handshake, which is why the cluster port must be on a trusted network.
- The active node advertises a freshly generated private key and a self-signed certificate through the encrypted storage, and each standby opens a mutually authenticated connection using them.
- The operator installs a shared certificate on every node, which is why all nodes have to be provisioned with the same material.
- The nodes derive the material from the unseal key, so any node that has been unsealed with the correct shares can open the channel without any advertisement.