drGrove / drGrove/mtls-cli

Implement via PKCS#11

Open
#55 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
29
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Instead of loading the certificate into the browser store and all the incompatibilites and annoyances that comes with, I think mtls-cli could be implemented as a PKCS#11 library:
Browsers support using PKCS#11 to load certificates and handle their private key operations.

Last time I looked into this the easiest way to create virtual/custom PKCS#11 devices was libtpm2 (https://github.com/tpm2-software). By using e.g. [libtpm2-pkcks11](https://github.com/tpm2-software/tpm2-pkcs11) you could even bind the key to a specific machine, accomplishing a major goal in the zero-trust networking paper.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.