You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Each XTM Composer instance has its own RSA private key (used for connector credentials encryption). The key is loaded as a singleton at startup (src/main.rs — private_key()). When migrating existing customers to a shared instance, the two former instances have different keys. Connectors encrypted with the old key won't decrypt with the new one.
Options
Support multiple keys (quick workaround): Allow the shared composer to hold both private keys and try decryption with each. Enables seamless migration without re-encrypting credentials on the platform side.
RSA key renewal/rotation (clean solution): Add the ability to rotate the RSA key on the platform side, so both platforms can be re-keyed to match the shared composer's key. Already tracked in feat: handle renewal of the RSA key #72.
Both options may be valuable — option 1 for migration, option 2 for ongoing operational needs.
Parent: #86
Context
Each XTM Composer instance has its own RSA private key (used for connector credentials encryption). The key is loaded as a singleton at startup (
src/main.rs—private_key()). When migrating existing customers to a shared instance, the two former instances have different keys. Connectors encrypted with the old key won't decrypt with the new one.Options
Both options may be valuable — option 1 for migration, option 2 for ongoing operational needs.