indygreg / indygreg/apple-platform-rs
Implement decryption for macOS keychain keys
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 854
- Forks
- 98
- PR merge metrics
- No merged PRs in 30d
Description
We have support for performing cryptographic signing using keys stored in macOS keychains. But we don't have support for decryption (needed for remote signing) because the Rust bindings to `SecurityFramework.framework` don't appear to have the APIs we need.
We'll likely need to teach the `security-framework` crate about the missing APIs in order to implement decryption.
As a workaround, you can export private keys from keychain to a PFX/.p12 file. This is probably less secure. But it will unblock using remote code signing with the keys.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reviewing the existing cryptographic signing support and the security-framework crate bindings for SecurityFramework.framework. Identify the missing APIs required for keychain-backed decryption, then verify that decryption works for remote code signing without exporting the private key.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- macos, rust
- Domain
- cryptography, operating-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100