indygreg / indygreg/apple-platform-rs

Implement decryption for macOS keychain keys

Open
#7 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

apple-codesign
Dominant language
Rust
Stars
854
Forks
98
PR merge metrics
No merged PRs in 30d

Description

We have support for performing cryptographic signing using keys stored in macOS keychains. But we don't have support for decryption (needed for remote signing) because the Rust bindings to `SecurityFramework.framework` don't appear to have the APIs we need.

We'll likely need to teach the `security-framework` crate about the missing APIs in order to implement decryption.

As a workaround, you can export private keys from keychain to a PFX/.p12 file. This is probably less secure. But it will unblock using remote code signing with the keys.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the existing cryptographic signing support and the security-framework crate bindings for SecurityFramework.framework. Identify the missing APIs required for keychain-backed decryption, then verify that decryption works for remote code signing without exporting the private key.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos, rust
Domain
cryptography, operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.