Pairing
Enrollment is a short code the operator carries. The code is not a credential: one certificate issuance, then worthless. The client's private key is born on the client and never crosses the wire. There is no registration blob to paste and no actana core add.
Both ends live in one actana binary. actana pair new runs on the Core and mints the code. The client spends it — actana core pair on the machine being paired, Add a Core in the Panel, or pairWithCore from a program.
Since 0.4.3, pair new at a terminal prints a handout: the code, fingerprint, session and expiry in one framed block, with the Panel steps and a ready-to-paste actana core pair command — every value already filled in — underneath. Carrying the four fields by hand still works; you just rarely have to.
The one manual step that remains is the point of the design: compare the CA fingerprint before the code is sent.
sequenceDiagram
participant Op as Operator
participant Core
participant Client as Client
Op->>Core: actana pair new
Core-->>Op: handout — code, fingerprint, session, expiry
Op->>Client: paste the command (or carry the fields)
Client->>Core: identify (sends nothing)
Core-->>Client: CA in the handshake
Client->>Op: show fingerprint
Op->>Client: confirm match
Client->>Core: redeem CSR with the code
Core-->>Client: endpoint, CA, client cert, bearer
In this section
- How Pairing Works — the protocol: mint, first contact, the fingerprint, redeem, refusals.
- Create a Pairing Code —
actana pair new, the handout, and the code lifecycle: list, revoke, rotate. - Actana CLI Pairing —
actana core pairon the machine being paired. - Panel Pairing — Add a Core, and the first-run wizard.
- SDK Pairing —
pairWithCorefrom@actana/sdk. - Pairing Troubleshooting — what each refusal means.