GoogleCloudPlatform / GoogleCloudPlatform/kms-integrations

Ability to disambiguate key versions in pkcs11 URIs

Open
#52 0 comments 0 reactions 0 assignees View on GitHub
known issue
Dominant language
C++
Stars
47
Forks
24
PR merge metrics
No merged PRs in 30d

Description

Currently the version of a key is only included in the `id` (`CKA_ID`), while the `object` (`CKA_LABEL`) is only set to the key name. So a URL like `pkcs11:object=some-key` would select multiple versions of the key which seems to often confuse libraries like the OpenSSL Engine of libp11. It would be nice if there was some other attribute there that can allow selecting a key by using `object`, and the key version (Not sure how possible is this using the PKCS#11 interface), or maybe just adding the version to the `object` part, possibly with a config key. As IDs are expected to be percent encoded in such URLs and have a 100 character limit in some libraries which can be annoying.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.