Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Discuss: Support for automated decrypt / remote unlock for apps - clevis / tang ? #10

Open
ieugen opened this issue Mar 20, 2024 · 2 comments

Comments

@ieugen
Copy link

ieugen commented Mar 20, 2024

This might be in a companion library but Clevis and Tang implement a protocol for automated decryption (remote unlock).

It might be useful for tempel to support at least the client part if not more.

Clevis and Tang provide a way for a system to decrypt secrets if it's in a specific network or has access to TPM.
Seemed quite ingenious to me and worth mentioning in the context of tempel.

Might be useful for starting an application that needs to decrypt a bunch of service (the admin) credentials without requiring user input.

https:/latchset/clevis
https:/latchset/tang

@ptaoussanis
Copy link
Member

Hi there! I've not heard of either of these before, thanks for the links. Will take a look next time I'm doing batched work on Tempel - though please note that in principle my current plan is to keep Tempel's scope limited to more or less what it does now.

(Which of course doesn't exclude the possibility of interested folks building higher-level protocols on top of it, etc. 👍)

@ieugen
Copy link
Author

ieugen commented Mar 21, 2024

Thanks, sounds reasonable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants