keybase / keybase/keybase-issues

Feature suggestion: Ability to add X.509 certificates as identity proofs

Open
#1,732 3 comments 7 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

There are some situations when people have verified/trusted third party issued X.509 certificates (e.g. code signing certificates bought from trusted CAs and used for signing WIndows applications).

I suggest adding ability to prove X.509 identity on Keybase by:
1. publishing a third party trusted X.509 certificate (e.g. code signing certificate) on Keybase (without private key, of course; most likely including intermediate certificates)
2. signing Keybase request (containing fingerprints of user's PGP key **and** X.509 certificate) by user's PGP key **and** X.509 certificate
3. publishing both signatures on Keybase as the proof

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by reviewing Keybase's existing identity-proof flow and determine how trusted X.509 certificates and signatures would fit; done means the proposed certificate publication and dual-signature proof flow is implemented and verifiable.

Written by the indexing model from the issue text.

Assessment

Tech stack
cryptography
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.