Important: Release 0.9 Feature
Tessera now supports remote enclaves for increased security. Please refer to the wiki for details.
Tessera is a stateless Java system that is used to enable the encryption, decryption, and distribution of private transactions for Quorum.
Each Tessera node:
-
Generates and maintains a number of private/public key pairs
-
Self manages and discovers all nodes in the network (i.e. their public keys) by connecting to as few as one other node
-
Provides Private and Public API interfaces for communication:
- Private API - This is used for communication with Quorum
- Public API - This is used for communication between Tessera peer nodes
-
Provides two way SSL using TLS certificates and various trust models like Trust On First Use (TOFU), whitelist, certificate authority, etc.
-
Supports IP whitelist
-
Connects to any SQL DB which supports the JDBC client
To build and install Tessera:
- Clone this repo
- Build using Maven (see below)
Tessera can use either the jnacl or kalium NaCl cryptography implementations. The implementation to be used is specified when building the project:
mvn install
Install libsodium as detailed on the kalium project page, then run
mvn install -P kalium
java -jar tessera-dist/tessera-app/target/tessera-app-${version}-app.jar -configfile /path/to/config.json
See the
tessera-dist
README for info on the different distributions available.
Once Tessera has been configured and built, you may want to copy the .jar to another location, create an alias and add it to your PATH:
alias tessera="java -jar /path/to/tessera-app-${version}-app.jar"
You will then be able to more concisely use the Tessera CLI commands, such as:
tessera -configfile /path/to/config.json
and
tessera help
By default, Tessera uses an H2 database. To use an alternative database, add the necessary drivers to the classpath:
java -cp some-jdbc-driver.jar:/path/to/tessera-app.jar:. com.quorum.tessera.launcher.Main
For example, to use Oracle database:
java -cp ojdbc7.jar:tessera-app.jar:. com.quorum.tessera.launcher.Main -configfile config.json
DDLs have been provided to help with defining these databases.
Since Tessera 0.7 a timestamp is recorded with each encrypted transaction stored in the Tessera DB. To update an existing DB to work with Tessera 0.7+, execute one of the provided alter scripts.
A configuration file detailing database, server and network peer information must be provided using the -configfile
command line property.
An in-depth look at configuring Tessera can be found on the Tessera Wiki and includes details on all aspects of configuration including:
- Cryptographic key config:
- Using existing private/public key pairs with Tessera
- How to use Tessera to generate new key pairs
- TLS config
- How to enable TLS
- Choosing a trust mode
Tessera is the service used to provide Quorum with the ability to support private transactions, replacing Constellation. If you have previously been using Constellation, utilities are provided within Tessera to enable the migration of Constellation configuration and datastores to Tessera compatible formats. Details on how to use these utilities can be found in the Tessera Wiki.
- The Tessera Wiki provides additional information on how Tessera works, migrating from Constellation to Tessera, configuration details, and more.
- Quorum is an Ethereum-based distributed ledger protocol that uses Tessera to provide transaction privacy.
- Follow the Quorum Examples to see Tessera in action in a demo Quorum network.