ended3월 22일· 1 sources
ACME device attestation, smallstep and pkcs11: attezt
ACME 디바이스 증명(Device Attestation), smallstep, 그리고 PKCS#11: attezt
Why it matters
The author describes using step-ca for internal ACME TLS and SSH certificates with hardware-bound keys via TPM. After discovering that step-ca's device-attest-01 ACME challenge support is enterprise-only, they built 'attezt', an open-source attestation CA that enables TPM-based device identity verification for ACME servers implementing device-attest-01. The project aims to make hardware-bound device attestation accessible for personal infrastructure without enterprise licensing.
1
Sources
+0
24h
—
Growth
183d
Active
ACME device-attest-01step-caTPMatteztPKCS#11hardware-bound keys