aws / aws/aws-nitro-enclaves-cli

When using a KMS key as the private-key, How is the signing-certificate generated?

Open
#736 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
156
Forks
99
PR merge metrics
No merged PRs in 30d

Description

The documentation from [here](https://docs.aws.amazon.com/de_de/enclaves/latest/user/cmd-nitro-build-enclave.html) says that a KMS key arn can be used for the private-key and [this documentation ](https://docs.aws.amazon.com/de_de/enclaves/latest/user/set-up-attestation.html#pcr8) says how to generate a signing-certificate from a local private-key. But what is the process for generating the signing certificate when using a KMS key for the private key?

Is this feature only supported for customer managed keys CMK, where we already have access to the private-key?

Contributor guide

Open the contributing guide

Research direction

Start with the linked Nitro Enclaves build and attestation documentation, then trace how the private-key KMS ARN is handled. Clarify whether a signing certificate can be generated with KMS-backed keys, including the customer-managed-key question. Done means the documentation states the supported key types and the complete certificate-generation process or limitation.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, rust
Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.